From the Emudeck discord:

@everyone Hey everyone, apologies for the ping but since this is deemed as critical to the security of people's devices here, I will have to. Cemu (The Wii U emulator) was recently compromised by a malicious attacker using a known developers account, this compromise took place from May 6th to May 12th, and introduces malware that is known to steal passwords, SSH keys, GitHub tokens, and likely more they are not fully aware of at this moment. We recommend anybody who is on Linux or SteamOS to go into the EmuDeck app, Manage Emulators tab, Cemu, and click Reinstall/Update, and make sure the hash of the AppImage (Located in Home/Applications, right click Cemu AppImage, go into Properties, Checksums, and Calculate the SHA256 hash) matches the non-compromised version provided by the Cemu developers, if you have used Cemu from the dates I have mentioned, and the SHA256 hash does not match what is listed, assume your system may be compromised if it was ran. If you are on Windows, MacOS, or used the Flatpak version, you are not affected by this malware. More information regarding this attack can be found here. https://rentry.org/cemu-security-psa

The specifically affected packages were:

Cemu-2.6-x86_64.AppImage

cemu-2.6-ubuntu-22.04-x64.zip

you are viewing a single comment's thread
view the rest of the comments
[–] [S] 86 points 4 months ago (21 children)

Also I thought this part was interesting:

Special note for Israeli users: If the malware determines that your location is Israel (it does this via locale and timezone checks) then it has a 1:6 chance that it will play a loud siren sound and run rm -rf /, essentially attempting to wipe your filesystem.

  • source
  • hideshow 21 child comments
  • [–] 50 points 4 months ago* (4 children)

    It turns out the malware doesn't work because it runs subprocess.run(["rm", "-rf", "/*"])

    That will never delete anything, since there is no shell to expand the glob in /* here, so rm gets a literal /* as the path to delete 😭

  • source
  • parent
  • hideshow 4 child comments
  • [–] 44 points 4 months ago (3 children)

    This is why you test your code, people

  • source
  • parent
  • hideshow 3 child comments
  • [–] 8 points 4 months ago (2 children)

    Maybe now they'll figure out that they need to vote Netanyahu out of office for being a genocidal piece of shit

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 4 months ago (1 child)

    Unless the option --no-preserve-root is given, it should not execute.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 7 points 4 months ago

    Fun fact:

    rm -rf / requires —no-preserve-root to work whereas rm -rf /* doesn’t.

    That’s because the /* gets expanded by the shell before the command runs and it only sees the request to delete /var, /dev, /home, /usr,… recursively but not / specifically.

    On another note: This line in the code doesn’t run through a shell and thus this won’t work and it just tries to delete the literal path of /* recursively - and thus fails to do any damage…

  • source
  • parent
  • [–] 4 points 4 months ago (5 children)

    That’s not malware.

    That’s amazing.

  • source
  • parent
  • hideshow 5 child comments
  • [–] [S] 11 points 4 months ago (4 children)

    It also trys to steal passwords/keys/etc, the Russian roulette part is just extra for people in Israel.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 4 points 4 months ago (2 children)

    Is this considered Chaotic Good or Lawful Evil?

  • source
  • parent
  • hideshow 2 child comments