This is the first I’m hearing of this. Do you have any references?
[1] https://learn.thinkdiffusion.com/bria-ai-for-background-remo...
I would say that the "more secure way" is to just use ComfyUI without installing any obscure nodes from unknown developers. You can do pretty much anything using just the default nodes and the big node packs.
Doesn't mean that this guy was not a malicious actor, only that one shouldn't be so quick to cast stones without evidence.
Today's capture (before the repo got 404'd) has their belligerence spiel. https://web.archive.org/web/20240609135118/https://github.co...
This is the capture from 3 days prior: https://web.archive.org/web/20240525021402/https://github.co...
The author of the repo is claiming that their repo is hacked, but this is an obvious lie, because their very first GitHub commit is the one where they push the malware. Nobody would hack an empty GitHub account.
I don't know if the author of the repo is lying when they say that Nullbulge is behind the attack (perhaps the author is part of Nullbulge, perhaps not).
Was this the main method of GPT4 and Claude integrations for ComfyUI?