Umami is vulnerable - upgrade immediately

All umami instances have been infected with a persisting crypto miner. Umami was affected by the next.js CVE but quietly released a fix, so most of their users missed it

124 points · 17 comments · view on lemmy.world

17 Comments

non_burglar@lemmy.world · 36 pts · 264d (4 replies)

Link? Did you discover this yourself? There is no actual info here.

wildbus8979@sh.itjust.works · 55 pts · 264d (1 reply)
non_burglar@lemmy.world · 10 pts · 264d

Thank you!

Mubelotix@jlai.lu · 11 pts · 264d (1 reply)

All recently open issues are about this. I was a victim, but I'm not the first and people on reddit have done better investigations than I have. Look for the name of the process at the top

non_burglar@lemmy.world · 32 pts · 264d

Thanks.

For severe incidents like this, please post the most appropriate link, in this case https://github.com/umami-software/umami/issues/3852

Admins in self hosted usually don't have that much experience with real, active compromise and may panic, let's help them as much as possible.

I will add that Umami itself is not compromised, but vulnerable. That is a somewhat misleading title.

What was the vector? Did you have umami exposed publicly?

EncryptKeeper@lemmy.world · 33 pts · 263d

I don’t know about “all umami instances being infected” but they were certainly all vulnerable.

clb92@feddit.dk · 16 pts · 263d

All umami instances have been infected with a persisting crypto miner.

Source for that claim? Because vulnerable does not mean infected.

Also, I'm kinda glad my instance has been offline for a while now because of database trouble. That was lucky.

Bombastic@sopuli.xyz · 15 pts · 263d

Look inside

React2Shell

Just another day on the job

rayboy@lemmy.world · 8 pts · 264d (6 replies)

Wow I'm glad I happened to see this here. Thank you for the post. I was just thinking about putting all my services behind a VPN too, I think I'm going to go ahead and put that at the top of the list...

GottaHaveFaith@fedia.io · -6 pts · 263d (5 replies)

I don't think a vpn would help here

GraveyardOrbit@lemmy.zip · 10 pts · 263d (4 replies)
[ removed ]
EncryptKeeper@lemmy.world · 10 pts · 263d

Yeah but Umami is an analytics engine powered by client side tracking. If it was behind a VPN it would be useless.

GottaHaveFaith@fedia.io · 2 pts · 263d

Yes I re-read the cve, I thought it was an issue with an npm package with a cryptominer

frongt@lemmy.zip · 1 pts · 263d (1 reply)

Unless it was the software package itself that was compromised.

EncryptKeeper@lemmy.world · 2 pts · 263d

It was not

rehydrate5503@lemmy.world · 3 pts · 261d (1 reply)

This could explain why my 4C/8T VPS started hitting 100% CPU usage shortly after boot with like next to nothing else running on it.

rehydrate5503@lemmy.world · 1 pts · 256d

Yup, umami was the culprit in my case. Quick update and it’s all running smooth again.

corsicanguppy@lemmy.ca · -6 pts · 263d

I see it's running Ansible. That's an obvious risk.