cm0002@europe.pub to Linux@programming.dev · 2 days agoThe security situation with the Arch Linux AUR got a lot worsewww.gamingonlinux.comexternal-linkmessage-square41fedilinkarrow-up1178arrow-down15cross-posted to: [email protected]
arrow-up1173arrow-down1external-linkThe security situation with the Arch Linux AUR got a lot worsewww.gamingonlinux.comcm0002@europe.pub to Linux@programming.dev · 2 days agomessage-square41fedilinkcross-posted to: [email protected]
minus-squarebrucethemoose@lemmy.worldlinkfedilinkarrow-up15·edit-22 days agoIt seems like some person with a bot just asked to maintain a bunch of orphaned packages, abusing the 2-week waiting period. Right? Thats why they used npm; off the shelf, almost “standard practice” credential harvesting malware. Nothing too fancy.
It seems like some person with a bot just asked to maintain a bunch of orphaned packages, abusing the 2-week waiting period. Right?
Thats why they used npm; off the shelf, almost “standard practice” credential harvesting malware. Nothing too fancy.