zopfli-rs / zopfli

A Rust implementation of the Zopfli compression algorithm.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Mildly suspicious owner

alecmocatta opened this issue · comments

Bejolithic is an owner of this crate, as of #1.

I just happened to notice that all 3 other crates they own are copies of other crates, renamed, stripped of attribution and relicensed:

https://crates.io/crates/forage -> https://crates.io/crates/maimo: FuzzrNet/Forage#6
https://crates.io/crates/wasmpng -> https://crates.io/crates/wasimage: datatrash/wasm-png#1
https://crates.io/crates/bbcli -> https://crates.io/crates/wingcli: losfair/blueboat#90

Probably innocuous, but thought it might be worth raising to nip in the bud potential for a supply-chain attack on users of this crate.

Thanks for raising up this issue!

There were many, many more instances of not only crates, but entire repos, blog posts and more that I found blatantly copied without any form of attribution. This behavior is definitely suspicious and there's nowhere I can find that Bejolithic contributed to zopfli-rs, so I have removed this user from the organization.

This looks wrong indeed. These aren't just forks, but crates with completely replaced authorship metadata without any credit, and inappropriately changed license.

I've removed them from zopfli owners.