frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Supply Chain Alert: Sipeed's Official COMTools Software Flagged as Trojan

4•dripmet•2h ago
Sipeed is a Chinese hardware manufacturer known for embedded AI systems, RISC-V development boards, and edge computing modules (K210 AI accelerators, MaixSense ToF cameras, LicheeRV boards). They're fairly established in the maker and embedded systems community.

I downloaded their official COMTools utility (serial communication tool for device configuration) directly from their distribution server at dl.sipeed.com - the link provided in their official documentation.

Multiple security scanners are flagging it as trojan malware:

VirusTotal: https://www.virustotal.com/gui/file/66b9b83687f4579e0de629eb63b9d41ef0c3cc2e4f03546d0fe6374de76c69f8/detection

Hybrid Analysis: https://hybrid-analysis.com/sample/66b9b83687f4579e0de629eb63b9d41ef0c3cc2e4f03546d0fe6374de76c69f8/690e6b0ff38090310e09c79d

More concerning than the detections is the observed behavior: - Random cmd.exe processes spawning periodically - Persistent background activity - BitLocker recovery triggered after offline virus scan - Suspicious network connections

This goes beyond typical false-positive behavior seen with some Chinese development tools (which sometimes lack proper code signing or use aggressive system access).

Two possibilities: 1. Supply chain compromise - their dl.sipeed.com server is serving modified binaries 2. Aggressive false positive (seems less likely given the behavioral indicators)

I'm currently comparing SHA256 hashes between the website version and their GitHub releases to determine if there's a discrepancy.

If this is a supply chain attack, it could affect a significant portion of the embedded systems development community, particularly those working with AI edge devices and RISC-V systems.

I've reported to Sipeed, Microsoft Security, and various security researchers. Has anyone else in the HN community used Sipeed products and can verify their COMTools installation?

SHA256 of flagged file: 66b9b83687f4579e0de629eb63b9d41ef0c3cc2e4f03546d0fe6374de76c69f8 Official (potentially compromised) source: https://dl.sipeed.com/shareURL/MaixSense/MaixSense_A010/software_pack/comtool

Ask HN: Where did the tech people on Twitter go?

2•stevage•2m ago•0 comments

New Daily Pill Could Be Life-Saving for Americans with High Cholesterol

https://www.smithsonianmag.com/smart-news/new-daily-pill-could-potentially-be-lifesaving-american...
1•geox•3m ago•0 comments

Refreshing Apache XML Infrastructure

https://blog.adamretter.org.uk/refreshing-apache-xml-infrastructure/
1•adamretter•4m ago•0 comments

Artificial Versifying (2019)

https://jeffreymbinder.net/?p=304
1•benbreen•6m ago•0 comments

Alex Karp Goes to War

https://www.wired.com/story/alex-karp-goes-to-war-palantir-big-interview/
2•aspenmayer•8m ago•1 comments

Standard Capital: Series A lead investor for 10% equity via application

https://www.standardcap.com/
1•nathanh•9m ago•0 comments

Echogarden is an easy-to-use speech toolset of speech processing tools

https://github.com/echogarden-project/echogarden
1•wahnfrieden•17m ago•0 comments

Show HN: EchoStack – Deployable Voice-AI Playbooks Powered by a Manifest System

https://getechostack.com
1•solomonayoola•20m ago•1 comments

Political Chinese Culture at Meta

https://www.teamblind.com/post/political-chinese-culture-at-meta-2vx8g0a1
4•DustinEchoes•24m ago•0 comments

AI Feynman: A Physics-Inspired Method for Symbolic Regression

https://arxiv.org/abs/1905.11481
2•openquery•25m ago•0 comments

You trained AI on the internet but forgot about estrogen

2•ghostprompt•26m ago•2 comments

Is it possible to get a Jr. developer job in Elixir?

2•bauldursdev•28m ago•2 comments

Who Uses REXX and Where?

https://rexxinfo.org/howard_fosdick_articles/who_uses_rexx_and_where/who_uses_rexx_and_where.html
2•shrubble•30m ago•1 comments

De-duplicating the desktops: Let's come together

https://www.theregister.com/2025/11/10/deduplicating_the_desktops/
2•occamrazor•30m ago•0 comments

Do We Need Another Presidential Physical Fitness Test?

https://www.medscape.com/viewarticle/do-we-need-another-presidential-physical-fitness-test-2025a1...
2•wjb3•30m ago•1 comments

EU's minimum wage faces judgment day

https://www.euractiv.com/news/eus-minimum-wage-faces-judgment-day/
3•tokai•34m ago•0 comments

A2UI: LLM-generated UI protocol (Google)

https://a2ui.org/
1•stansler•34m ago•1 comments

Show HN: Clarion: An AI-powered news curator emphasizing clarity over chaos

https://clarion.today/
1•radiusvector•34m ago•1 comments

SailPoint's Second Act

https://strategyofsecurity.com/p/sailpoints-second-act
2•mooreds•36m ago•0 comments

High-performance 2D graphics rendering on the CPU using sparse strips [pdf]

https://github.com/LaurenzV/master-thesis/blob/main/main.pdf
7•PaulHoule•37m ago•0 comments

Rad Power Bikes faces shutdown in January without new funding

https://techcrunch.com/2025/11/10/rad-power-bikes-faces-shutdown-in-january-without-new-funding/
3•mooreds•37m ago•0 comments

3D Heterogeneous Integration Powers New DARPA Fab

https://spectrum.ieee.org/3d-heterogeneous-integration
3•rbanffy•38m ago•0 comments

Duke Explores Private Credit in Potential First for Utilities

https://www.bloomberg.com/news/articles/2025-11-10/duke-explores-private-credit-in-potential-firs...
2•petethomas•39m ago•0 comments

Cybersecurity breach at Congressional Budget Office remains a live threat

https://www.politico.com/live-updates/2025/11/10/congress/cbo-still-under-threat-00644930
9•mooreds•39m ago•0 comments

Prenatal Exposure to Air Pollutants Tied to Increased Autism Risk

https://www.medscape.com/viewarticle/prenatal-exposure-air-pollutants-tied-increased-autism-risk-...
3•wjb3•39m ago•2 comments

Episteme: A New System for Science

https://epistemescience.substack.com/p/introducing-episteme
1•JohnHammersley•41m ago•1 comments

Apple Releases Temporal SDK for Swift

https://www.swift.org/blog/swift-temporal-sdk/
6•thelonelygod•44m ago•0 comments

Investors' dumb transhumanist ideas setting back neurotech progress, say experts

https://www.theguardian.com/science/2025/nov/10/investors-transhumanist-ideas-neurotech-progress-...
3•amarcheschi•47m ago•1 comments

What Is the Ozma Problem, and Why Does It Matter?

https://www.fascinatingworld.org/post/what-is-the-ozma-problem-and-why-does-it-matter
2•Hooke•47m ago•0 comments

Are we doomed? Review of books on depopulation and extinction

https://www.lrb.co.uk/the-paper/v47/n21/david-runciman/are-we-doomed
3•mitchbob•47m ago•1 comments