"Dodgy" FabFilter Mac installer from team GMATIC left "CoreAudio.app" on system

Discussion in 'Mac / Hackintosh' started by Vaultnaemsae, Feb 28, 2025 at 6:01 PM.

  1. shinyzen

    shinyzen Audiosexual

    Joined:
    Sep 28, 2023
    Messages:
    887
    Likes Received:
    568
    technically, rug pulls arent really theft. I mean, they are, but legally, you bought a coin, with likely no promises, not even knowing who the dev is etc, thats on you. Your transaction getting interupted by malware is outright theft. I have a friend who had 100k stolen by a sim card swap, he contacted coinbase, and they contacted police, and they actually caught the guy.
     
  2. heero

    heero Newbie

    Joined:
    Jun 30, 2019
    Messages:
    24
    Likes Received:
    1
    dox-gate? what was that?
     
  3. clone

    clone Audiosexual

    Joined:
    Feb 5, 2021
    Messages:
    7,963
    Likes Received:
    3,487
    you can see everything this installer tries to do in Suspicious Package. https://mothersruin.com/software/SuspiciousPackage/

    Suspicious Package shows about 2500 warnings on this one installer. File size mismatches, stuff that show it wants to use "admin" when it actually tries to get Wheel (root).

    The version of "coreaudio.app" will not even run on Mojave. Certain files are obfuscated, like monitor.mom and monitor.omo.

    With the comment above that sounds like "conspiracy theory" re: "dox-gate", it would not surprise me at all if they were related. It's the first thing I thought when I took this file apart. This looks like the work of the same skill level script kiddie. It's not a "stolen release" in the normal sense, with someone trying to gain money or credit for someone else's work. It's like someone melting a trojan server into MS Paint but made attractive to possible downloaders of Fabfilter plugins. (maybe even Team VR members themselves! lol yeah right).

    Fabfilter has never done anything like this about their plugins being shared before. Consider the timing. Maybe keep your eyes open for some Windows attempt with something else.
     
  4. sisyphus

    sisyphus Audiosexual

    Joined:
    Apr 29, 2014
    Messages:
    1,597
    Likes Received:
    680
    ...and those f'ers just reposted it....

    I know the mods have to deal with whack-a-mole sometimes, and there aren't enough hands on deck to manually approve posts I imagine in a timely fashion, but there is a solution in need of finding here I think....
     
  5. typical-love

    typical-love Producer

    Joined:
    May 9, 2020
    Messages:
    269
    Likes Received:
    120
    Another dodgy release... stay on your toes everyone. I think we need more vetting of uploads by new teams/uploaders now.
     
  6. omiac

    omiac Moderator Staff Member

    Joined:
    May 3, 2024
    Messages:
    227
    Likes Received:
    227
    Already removed. It was queued prior to the ban issued... I/we are on it!

    Please, if anyone sees something suspicious like this, use PM to contact myself and/or PiRAT ASAP, report it and post a warning notice comment letting other members know whats up. TY!
     
  7. saccamano

    saccamano Audiosexual

    Joined:
    Mar 26, 2023
    Messages:
    1,456
    Likes Received:
    596
    Location:
    CBGB omfug
    GMATIC eh? Good to know if I ever see any "releases" by that group for winOS to simply ignore em...
     
  8. Vaultnaemsae

    Vaultnaemsae Newbie

    Joined:
    Jun 28, 2017
    Messages:
    7
    Likes Received:
    0
    Thank you to the community for all the additional information.

    I have a full backup of my system prior to the installation. I’m not sure if it a nuclear option to revert to that if I’ve simply removed the “CoreAudio.app”.

    One earlier post indicated that simply removing the app would be OK and the only threat would be if one had transacted in crypto presumably after launching the dodgy app, due to the presence of a keylogger.

    But another post indicates that there were 2500 warnings against the app when they inspected the package contents. Seems like there may be more to it than simple removal.
     
  9. odod

    odod Rock Star

    Joined:
    Jun 5, 2011
    Messages:
    849
    Likes Received:
    416
    GMatic just posted Rev1 .. what a dick!
     
  10. loveriuz

    loveriuz Producer

    Joined:
    Jan 1, 2022
    Messages:
    219
    Likes Received:
    97
    Location:
    East of Jupiter
    Good it wasn't a DOGE Coin stealer, my stuff is safe :disco:
     
  11. clone

    clone Audiosexual

    Joined:
    Feb 5, 2021
    Messages:
    7,963
    Likes Received:
    3,487
    While I would feel safe just deleting "CoreAudio.app" and the plugins; the reason why for me is because I do not have SIP disabled, and because I know my firewalls are not going to just allow something like that out to send any data ex: telemetry or passwords. I went through all the receipts and post-install scripts. The only one that calls Coreaudio.app is the post install script for Simplon.

    But if I had a brand new time machine backup, i'd go back to it anyway.
     
Loading...
Loading...