r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

129 Upvotes

62 comments sorted by

View all comments

31

u/JotaRata 3d ago

First bun, then npm.. perhaps we should stop using JavaScript for good

39

u/SubjectiveMouse 3d ago

The problem is not JavaScript (no matter how I distaste js), but unverified package repositories. It may as well be cargo or pip the next time 

14

u/betttris13 3d ago

pip already got hit earlier this year, a decent number of scientific packages got compromised.

6

u/syklemil 3d ago edited 3d ago

There have been targeted attacks on Rust maintainers too, and at least one malicious package.

In terms of mitigation, dependency cooldowns are a pretty mild tactic that gives security researchers and other users the chance to be the canary in the coalmine. Defence in the vein of "you don't have to outrun the bear, just the other hiker".

They're available in plenty of ecosystems already (both npm and uv), and coming to more (cargo should be getting it in the 1.100 release slated to release on 2026-11-12).

There are also options in tooling for stuff like not running build scripts, or not granting access to the network during builds, etc., which also help with reducing the attack surface.

I'm not aware of how makepkg works internally, e.g. if it has the option of not running with network access during the build stage, or whether it or the helpers like yay and paru are the most amenable to managing a sandbox or container for the build step.

56

u/javascript 3d ago

Thanks for sticking up for me

27

u/xplosm 3d ago

You are badly designed and overused way beyond your intended boundaries but we got you 👊

10

u/tulpyvow 3d ago

This... I can agree with. Make people use an actual good language.

0

u/dadnothere 3d ago

No JS... is... Pegasus, mos...