A malicious Pidgin plugin
The developers of the Pidgin chat programhave announced thata malicious plugin had been listed on its third-party plugins list for overone month. This plugin included a key logger and could capturescreenshots.
It went unnoticed at the time that the plugin was not providing anysource code and was only providing binaries for download. Goingforward, we will be requiring that all plugins that we link to havean OSI Approved Open Source License and that some level of duediligence has been done to verify that the plugin is safe forusers.