The Libretro community, which is involved in the development of a game console emulator and a distribution for creating game consoles , about a breach of project infrastructure elements and vandalism in the repositories. Attackers were able to access the build server (buildbot) and the repositories on GitHub.
On GitHub, attackers gained access to all of the Libretro organization by exploiting the account of a trusted project member. The attackers' activity was limited to vandalism — they attempted to wipe the content of the repositories by introducing an empty initial commit. During the attack, all repositories listed on three of the nine pages of Libretro's GitHub repository list were cleared. Fortunately, the act of vandalism was blocked by developers before the attackers reached the key repository. .
On the build server, the attackers damaged services responsible for generating nightly and stable builds, as well as organizing (netplay lobby). Malicious activity on the server was limited to deleting content. There were no recorded attempts to substitute files or make changes to the RetroArch builds and core packages. Currently, the Core Installer, Core Updater, and Netplay Lobby, along with associated sites and services (Update Assets, Update Overlays, Update Shaders), are not functioning.
The main issue the project faced after the incident was the lack of an automated backup process. The last backup of the buildbot server was made several months ago. Developers explained the problems by the absence of funds for an automated backup system due to a limited budget for maintaining infrastructure. Developers plan not to restore the old server but to launch a new one, which had been in their plans. In this case, builds for primary systems such as Linux, Windows, and Android will be launched immediately, but it will take time to restore builds for specialized systems like game consoles and old MSVC builds.
It is assumed that restoring the contents of the cleaned repositories and identifying the attacker will be aided by GitHub, to whom a corresponding request has been sent. So far, it is only known that the hack was carried out from the IP address 54.167.104.253, indicating that the attacker likely used a compromised virtual server in AWS as an intermediary. Information regarding the method of penetration has not been disclosed.
Source: opennet.ru
