All umami instances have been infected with a persisting crypto miner. Umami was affected by the next.js CVE but quietly released a fix, so most of their users missed it
All umami instances have been infected with a persisting crypto miner. Umami was affected by the next.js CVE but quietly released a fix, so most of their users missed it
17 Comments
non_burglar@lemmy.world · 36 pts · 264d
Link? Did you discover this yourself? There is no actual info here.
wildbus8979@sh.itjust.works · 55 pts · 264d
https://github.com/umami-software/umami/issues/3852
non_burglar@lemmy.world · 10 pts · 264d
Thank you!
Mubelotix@jlai.lu · 11 pts · 264d
All recently open issues are about this. I was a victim, but I'm not the first and people on reddit have done better investigations than I have. Look for the name of the process at the top
non_burglar@lemmy.world · 32 pts · 264d
Thanks.
For severe incidents like this, please post the most appropriate link, in this case https://github.com/umami-software/umami/issues/3852
Admins in self hosted usually don't have that much experience with real, active compromise and may panic, let's help them as much as possible.
I will add that Umami itself is not compromised, but vulnerable. That is a somewhat misleading title.
What was the vector? Did you have umami exposed publicly?
EncryptKeeper@lemmy.world · 33 pts · 263d
I don’t know about “all umami instances being infected” but they were certainly all vulnerable.
clb92@feddit.dk · 16 pts · 263d
Source for that claim? Because vulnerable does not mean infected.
Also, I'm kinda glad my instance has been offline for a while now because of database trouble. That was lucky.
Bombastic@sopuli.xyz · 15 pts · 263d
Just another day on the job
rayboy@lemmy.world · 8 pts · 264d
Wow I'm glad I happened to see this here. Thank you for the post. I was just thinking about putting all my services behind a VPN too, I think I'm going to go ahead and put that at the top of the list...
GottaHaveFaith@fedia.io · -6 pts · 263d
I don't think a vpn would help here
GraveyardOrbit@lemmy.zip · 10 pts · 263d
EncryptKeeper@lemmy.world · 10 pts · 263d
Yeah but Umami is an analytics engine powered by client side tracking. If it was behind a VPN it would be useless.
GottaHaveFaith@fedia.io · 2 pts · 263d
Yes I re-read the cve, I thought it was an issue with an npm package with a cryptominer
frongt@lemmy.zip · 1 pts · 263d
Unless it was the software package itself that was compromised.
EncryptKeeper@lemmy.world · 2 pts · 263d
It was not
rehydrate5503@lemmy.world · 3 pts · 261d
This could explain why my 4C/8T VPS started hitting 100% CPU usage shortly after boot with like next to nothing else running on it.
rehydrate5503@lemmy.world · 1 pts · 256d
Yup, umami was the culprit in my case. Quick update and it’s all running smooth again.
corsicanguppy@lemmy.ca · -6 pts · 263d
I see it's running Ansible. That's an obvious risk.