The most blatant security backdoor yet seen in an internet router has been found in a range of models sold under multiple brand names. A major challenge to avoiding these kinds of embedded malware threats is that so many Chinese-made routers are sold under different brands, sometimes with different claimed countries of origin. Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server. The researchers say that it poses the biggest risk yet seen because it initiates the contact with its command and control servers. A unit sitting behind three layers of firewall in a hotel back office is exactly as reachable as one with a public IP, provided it can get to the [command server].