Remove malware planted via exposed dev-mode frontend

The frontend container ran `next dev` bound to 0.0.0.0:3000 with the
host source directory bind-mounted rw into it. Over months this let
attackers write files directly onto the host filesystem, which then
got swept into git by an unrelated Gitea ZIP restore. Removes 4 UPX-
packed ELF binaries and a defacement marker (cox.txt/html).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
This commit is contained in:
ogrechkoandClaude Sonnet 5 committed 2026-09-03 04:03:32 +00:00
1 parent e9cd22d36f
commit ee4562530a
6 files changed
-2

No files matched your search

BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
-1
View File
@@ -1 +0,0 @@
hacked by trenggalek6etar
-1
View File
@@ -1 +0,0 @@
hacked by trenggalek6etar