frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Supply Chain Alert: Sipeed's Official COMTools Software Flagged as Trojan

5•dripmet•9h ago
Sipeed is a Chinese hardware manufacturer known for embedded AI systems, RISC-V development boards, and edge computing modules (K210 AI accelerators, MaixSense ToF cameras, LicheeRV boards). They're fairly established in the maker and embedded systems community.

I downloaded their official COMTools utility (serial communication tool for device configuration) directly from their distribution server at dl.sipeed.com - the link provided in their official documentation.

Multiple security scanners are flagging it as trojan malware:

VirusTotal: https://www.virustotal.com/gui/file/66b9b83687f4579e0de629eb63b9d41ef0c3cc2e4f03546d0fe6374de76c69f8/detection

Hybrid Analysis: https://hybrid-analysis.com/sample/66b9b83687f4579e0de629eb63b9d41ef0c3cc2e4f03546d0fe6374de76c69f8/690e6b0ff38090310e09c79d

More concerning than the detections is the observed behavior: - Random cmd.exe processes spawning periodically - Persistent background activity - BitLocker recovery triggered after offline virus scan - Suspicious network connections

This goes beyond typical false-positive behavior seen with some Chinese development tools (which sometimes lack proper code signing or use aggressive system access).

Two possibilities: 1. Supply chain compromise - their dl.sipeed.com server is serving modified binaries 2. Aggressive false positive (seems less likely given the behavioral indicators)

I'm currently comparing SHA256 hashes between the website version and their GitHub releases to determine if there's a discrepancy.

If this is a supply chain attack, it could affect a significant portion of the embedded systems development community, particularly those working with AI edge devices and RISC-V systems.

I've reported to Sipeed, Microsoft Security, and various security researchers. Has anyone else in the HN community used Sipeed products and can verify their COMTools installation?

SHA256 of flagged file: 66b9b83687f4579e0de629eb63b9d41ef0c3cc2e4f03546d0fe6374de76c69f8 Official (potentially compromised) source: https://dl.sipeed.com/shareURL/MaixSense/MaixSense_A010/software_pack/comtool

Comments

zepan•3h ago
It is a Trojan false alarm, introduce by "pyinstaller" The software is opensource, feel free to review/compile it: https://github.com/sipeed/MetaSense-ComTool https://github.com/Neutree/COMTool/issues/40 https://github.com/pyinstaller/pyinstaller/issues/4852

Ask HN: What Are You Working On? (Nov 2025)

367•david927•1d ago•1109 comments

Is there open source alternative for VAPI or retellai?

6•p_srivastav•1h ago•5 comments

Ask HN: How to grow and become more employable when working with outdated tech?

3•mattfrommars•3h ago•4 comments

Ask HN: How would you set up a child’s first Linux computer?

214•evolve2k•1d ago•287 comments

Ask HN: How do you get over the fear of sharing code?

67•sodokuwizard•1d ago•89 comments

Supply Chain Alert: Sipeed's Official COMTools Software Flagged as Trojan

5•dripmet•9h ago•1 comments

Ask HN: Why has typing on a phone not improved in ~20 years?

7•mvkel•13h ago•9 comments

When the Firefighter Looks Like the Arsonist: AI Safety Needs IRL Accountability

4•fawkesg•13h ago•0 comments

Ask HN: Where did the tech people on Twitter go?

8•stevage•7h ago•13 comments

Ask HN: My family business runs on a 1993-era text-based-UI (TUI). Anybody else?

314•urnicus•5d ago•307 comments

Tell HN: X is opening any tweet link in a webview whether you press it or not

646•stillatit•6d ago•516 comments

Ask HN: Who is hiring? (November 2025)

398•whoishiring•1w ago•556 comments

Ask HN: Why do designers have repugnant websites?

15•admissionsguy•1d ago•10 comments

Ask HN: Do you let your kids use ChatGPT?

7•eibrahim•1d ago•9 comments

Valori – A Python-native Vector Database I built from scratch

8•varshith17•1d ago•9 comments

Ask HN: How do you deal with eye strain as a developer?

4•deterministic•1d ago•8 comments

Ask HN: Who wants to be hired? (November 2025)

197•whoishiring•1w ago•458 comments

Ask HN: Is AI code assistance fundamentally unenforceable without hooks?

4•meloncafe•1d ago•2 comments

Tell HN: Mechanical Turk is twenty years old today

94•csmoak•1w ago•62 comments

YouTube A/B testing removing playback speed controls

7•dotancohen•1d ago•8 comments

Ask HN: Why doesn't USPS act as a payment processor?

11•piratesAndSons•1d ago•8 comments

Ask HN: Where to begin with "modern" Emacs?

225•weakfish•1w ago•121 comments

Ask HN: What's a Purchase You Regret?

11•znpy•2d ago•37 comments

Ask HN: Windows/Linux software that has no real equivalent on macOS?

9•fastily•2d ago•21 comments

Ask HN: Any actual AI projects in production at bigcorp?

4•meetingthrower•1d ago•4 comments

LLMs let me maintain my PostgreSQL extension for PRQL after becoming a parent

5•kaspermarstal•1d ago•0 comments

Ask HN: What is the most important thing in life?

14•awesomehry•3d ago•30 comments

You've reached the end!