All SCP (Secure Copy Protocol) implementations from the last 36 years, since 1983, are vulnerable to four security bugs that allow a malicious SCP server to make unauthorized changes to a client’s (user’s) system and hide malicious operations in the terminal.
Well holy shit! Tell everyone you know.