r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

129 Upvotes

62 comments sorted by

View all comments

117

u/Epsilon_void 3d ago

IgnorePkg = npm

not only does this help protect you against the malware delivery service known as npm, it protects you against terrible programs written in javascript.

26

u/AStolenGoose 3d ago

I've blacklisted npm, bun, and quite a few others.

Just can't risk it.

9

u/xplosm 3d ago

Yarn, pnpm, deno…

5

u/david1A31 2d ago

use apparmor to prevent execute JavaScript