Bartosz Golaszewski on Nostr: This is the first time I'm posting anything here but I figured this may be the right ...
This is the first time I'm posting anything here but I figured this may be the right audience.
I've never run into something like this and I don't quite know what to make of it. I'm the author and maintainer of libgpiod. The official git repository is the one at kernel.org[1]. There's also a github mirror[2] as well as a documentation page[3] at readthedocs that I maintain.
I noticed (purely by chance) that there's a new website at libgpiod.com that's been created recently. I have nothing to do with it. It's clearly AI-generated but it redirects to my github. It's a 2 month old domain, anonymized registrar, protected by Cloudflare and NeoProtect and a Swedish host behind that.
Clearly someone went to a great length to stay anonymous. I'm afraid of falling victim to some new elaborate supply chain attack. What should I do about it (if anything)? Has anyone else experienced something similar?
[1]
https://git.kernel.org/pub/scm/libs/libgpiod/libgpiod.git/
[2]
https://github.com/brgl/libgpiod
[3]
https://libgpiod.readthedocs.io/Published at
2026-06-13 17:05:34 UTCEvent JSON
{
"id": "98b7faf921dcdea24e7953a01f65178ba9cc3c5069706a26f3ccf4b4e6f0508b",
"pubkey": "b71ef7dcf8923422abd70ba124b3fe393a916a7074ea4eae16f7dc12993c5784",
"created_at": 1781370334,
"kind": 1,
"tags": [
[
"proxy",
"https://social.kernel.org/objects/bc6c59fe-a58c-47f7-9f1a-604d21b7f003",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://social.kernel.org/objects/bc6c59fe-a58c-47f7-9f1a-604d21b7f003",
"pink.momostr"
],
[
"-"
]
],
"content": "This is the first time I'm posting anything here but I figured this may be the right audience.\r\n\r\nI've never run into something like this and I don't quite know what to make of it. I'm the author and maintainer of libgpiod. The official git repository is the one at kernel.org[1]. There's also a github mirror[2] as well as a documentation page[3] at readthedocs that I maintain.\r\n\r\nI noticed (purely by chance) that there's a new website at libgpiod.com that's been created recently. I have nothing to do with it. It's clearly AI-generated but it redirects to my github. It's a 2 month old domain, anonymized registrar, protected by Cloudflare and NeoProtect and a Swedish host behind that.\r\n\r\nClearly someone went to a great length to stay anonymous. I'm afraid of falling victim to some new elaborate supply chain attack. What should I do about it (if anything)? Has anyone else experienced something similar?\r\n\r\n[1] https://git.kernel.org/pub/scm/libs/libgpiod/libgpiod.git/\r\n[2] https://github.com/brgl/libgpiod\r\n[3] https://libgpiod.readthedocs.io/",
"sig": "9381c9094d84de83792ce3aea868f4c3ddea9a649add5b020ea098fadd75cdd1b4591d353b505855a74d06789ae47a54926b49af98e5f55ffcf7e5560d6f4768"
}