MakuluLinux (6.4M Downloads) Ships Persistent Backdoor from Developer's Own C2
by werai on 1/29/2026, 6:18:22 PM
https://werai.ca/security-disclosure.html
Comments
by: sgc
This is why I won't use random distros, even if they have better features. It's just one more point of failure, one more point of unnecessary trust. I would rather fight to deal with specific problems with specific apps on one of the handful of core distros with long histories.
1/29/2026, 8:13:38 PM
by: sigio
The entire website looks shady, I can't imagine anyone installing this.<p>Was there any analysis on what the binaries do, because it could theoretically be a really badly implemented 'check for updates'.<p>Though I'm tempted to believe it is all part of a big scam :)
1/29/2026, 8:13:02 PM
by: thefz
> This is exactly why the Human Router architecture exists. In a world where you cannot even trust your operating system vendor, every decision — every execution — needs a governance gate.<p>> D = G × S. If G ≠ 1, D = 0. No action is routed without verified authority. No exceptions.<p>W... what?
1/29/2026, 8:14:51 PM
by: mrbluecoat
> Discovered by Steven Stobo (WeRAI / Haven AI)<p>AI pentesters and fuzzers will soon be the norm. And that's a good thing.
1/29/2026, 8:00:04 PM
by: whalesalad
I genuinely don't understand why anyone would use anything other than Debian (or Ubuntu), Fedora or Arch. Every other distro is a) based on one of those and b) is essentially just a package set + some wallpapers.
1/29/2026, 8:25:07 PM
by: OsrsNeedsf2P
This article is so painful to read. Do people not have shame in publishing slop?<p>> MakuluLinux is not just an OS with a backdoor. It's a delivery vehicle for a centralized AI-as-a-service platform.<p>But to the actual article point; it looks like this OS is designed to have these "integration features" that depend on a 3rd party connection. They could obviously be better - But the intent of them is very similar to how Android, Windows, or MacOS operate.
1/29/2026, 8:09:52 PM
by: LePetitPrince
[dead]
1/29/2026, 9:36:42 PM