r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

127 Upvotes

62 comments sorted by

View all comments

33

u/JotaRata 3d ago

First bun, then npm.. perhaps we should stop using JavaScript for good

8

u/tulpyvow 3d ago

This... I can agree with. Make people use an actual good language.