Is it just cgminer?
Anyone on BAMT affected?
Has anyone been affected that has api mode disabled?
I'm sorry, I'm sure these answers are out there already, but I don't have time to read through all the threads (hence why I asked if there's a consolidated page somewhere).
If it was MITM couldn't this be completely transparent, as it could pretend and report that it's on pool X when it's actually funnelling requests to pool Z. Hell, if it was smart and only redirected 5% of the hash nobody would probably notice. Rounded pennies on bank interest payments anyone?

What if it is malware, the malware itself hosts a stripped down pool, the reconnect goes there then the redirect goes to the malicious pool? Could be done with local DNS spoofing.
I wonder if we can just ask the NSA to forward us a copy of our network traffic so we can analyze what happened
