Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can anyone confirm there's nothing obviously malicious implanted in the code and they are legit?


Why on earth would you execute anything from the dump?


Well there was a critical git RCE less than 7 days ago that could be triggered by cloning a malicious repo so you might not have to execute anything to get owned


this is a torrent of a git repo, not using git to clone


It doesn't even have any git history either. Just pure source code with some ML models and training data.


You know why.


No, I really don't


These are various yandex products. Yandex is the Google of Russia, people will run the code out of curiosity alone.


lazy




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: