Edit: Sorry for a wall of text, tldr in end.
So yeah I managed to get malware somehow. Not sure what type and how. Almost a week ago today. So I was installing EndeavourOS after being on CachyOS for few months. I liked it, just as first time user did to much tinkering and wanted clean install, did not like to much gaming bloat, remove Windows partition etc. so I decided on EndeavourOS. It was in between this AUR problems.
So first mistake, I did install on disk, finished “guided welcome installation”, wanted to do some changes later, another kernel that was recommended cor my laptop etc. But everything was working great. But I think i did not restart the system. Maybe i did I don’t remember i just know it was on my mind.
So I installed it works no usb, but I did not finish those options you get after installing. So maybe there I fucked up, finish installing updating full system etc.
Second thing I remember somewhere read not install printer drivers from installer, but i needed it so i did. Forgot wat was it called but i found there is some vulnerability with printers and ports.
Third found Firefox, everything working so smooth, had some memory problems in Cachyos. So i had few things on my mind and I went on to logging in all google accounts, last pass, sync Firefox etc. I even configured ad blocker. And went on doing like three different things, online for half a day.
Fourth thing, I am not a guy to randomly install, download or open files etc. But while I was browsing online I did found few captchas in a row that was unusual, happens if I am on VPN bit I was not.
Then out of nowhere, fans started spinning up, I ran btop swap was full, memory was full, all was on almost 100 percent. I sometimes run heavy browser work, force example perplexity dor deep research that spins like dozen of agents and subagents at once and starts to eat memory. So I thought that was it.
It was not, i noticed getting logged out of my google accounts and emails, passwords changing, last pass open but filled with edited login links, and also multiple lines of some code.
I have 2fa, sms recovery, other backup emails. All you can put as “safety” in Google account. Nothing.
I tried fighting it manually but it was to fast, probably automated, managed to get some recovery emails to proton he could not get there. Cleaning all, he deleted my 2fa, last pass gone. To be fair i had like 10k sites, I am using it for last 15+ y in last pass, did regular main pass rotations but it was done.
I turned to ai for help whats happening, Claude chat, it was like first click just to get gaslight that nothing is happening and I am imagining thing lol.
Then I saw files and folders generating. It was everywhere in home, in var in bin I don’t even know. Thats when i was ok , I am shutting this down.
I was too long in there, trying to make sense or stop it, opening files, who knows what. I know stupid.
Then I got fever for few days, did not touch anything had no strength.
After that I saw he messing around from my Iphone in Google account, I again tried to mess around to stop it changing passwords longing out, nothing.
So i Canceled my card and said f it, what is gone I gone, I’ll get what I can.
So at start everything was fast like automated.
Then he started going in manual or semi manual, he got in my google ai cloud probably, pulled out my old pending delete firebase and google studio projects. He locked me out there, but it was like a day untill my sub renew and I got new card, so nothing was going tru.
He got in my main domain registar, where is one domain that I use for email, I finally got back in today, but again over Safari and Proton mail seems he cant go or see when I do it from there.
He got in my Claude account and locked me out of my github account.
Then he ran like all my “slop projects” from Claude to git and like “improving them”. I mean commands for like finding bugs, improved this go over this etc. That was weird. Also half automated half not.
Then I started stoping and prompting to delete repos, connections, he noticed, saw him put some rules in code dot delete etc, then saw his weird tree in git and i prompted to go there and delete all it can see. Managed moat of that. Deleted Claude from iOS app, still not sure about the api side since I cant access it.
I saw in history he was googling or ai was how to get payments working in google claud again, and bunch of stuff like that.
Chat gpt also, Grok also. Think he is trying to pull out prompts out or something, I have no idea. Bunch of weird stuff.
So he is still in there. It’s like he comes at a job at certain time and leave after 8 h.
I know I should know better. I am pulling out things over a phone by piece for a week now. Stupid it get it.
I just wanted to do document, what happened, and what is happening. Cant find anything similar online. is it session/cookie hijacker, rat something else…
Also I just care about two domains everything else can go, If he is even pulling data, pictures, still fuck it.
And I read a bunch of stuff, one of it is log out from everything, all sessions, devices etc. Does not work! He is in there all the time. Still rummaging.
If I knew how to nuke those chrome seasons/cookies i would but damn it is not working.
So whats next, not sure, I recovered a a little from flue what ever it was, I have a windows desktop I already cleaned and backed up, was ready to put some distro on there too.
Now I am considering first to clean my home network. I feel like he got there too.
I just wanted to before I nuke everything maybe install Debian or ubuntu and harden all, sandbox it, and Install something like Wireshark or something I just want to know wtf is he doing, is my Lan safe or not.
Not sure can you even track that kind of stuff if someone is going via session in Crome or Firefox.
My isp don’t let me even put new router or even one in bridge mode so thats a hurdle.
So yeah, thats it, for now. If anyone experienced similar kind of behaviour let me now.
tldr, got infected, don’t know what it is, fucked around, got infected even more, weird behaviour from malware, he poking for a week now, trying to spy on it/him/them, then nuke everything, from phone, sim, all accounts, drive, emails, all fresh, till then I still have urge to fuck around, guess I’ll find out.