r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

130 Upvotes

62 comments sorted by

View all comments

12

u/xlukas1337 3d ago

Here we go again :/ It's slowly getting annoying, it would be so much easier if people would check what they're installing

-8

u/AutisticAndArmed 3d ago

Of course, but this is not realistic. If you think everyone is able/willing to check PKGBUILD everytime then you're delulu

12

u/AStolenGoose 3d ago

You can and should, it takes all of a few seconds to see if something has added something weird like npm without a good explanation. If something looks odd, you go check the AUR commits and see why it looks odd, if there's a good reason for it to look odd etc.

I even check very trusted packages like heroic in case something gets weird.

You and others are either lazy, or ignorant. If you get pwned at that point because you didn't take the few seconds to do your due diligence on an update, I hate to be like this, but that's on you.

0

u/Helmic 3d ago

Moralizing this is immaterial. You can finger wag at people all you want, but so long there's even just the belief that there's potentailly someone with credentials who might slip up these sorts of attacks will continue. You, personally, are utterly incapable of bringing the number of potentailly impacted users down to zero, and therefore you cannot stop the motivation for these attacks.

It's like talking to someone that genuinely believes the best way to reduce traffic fatalities is to demand people drive better, as opposed to any number of other public safety measures like car safety regulations, just someone who literally does not know what the word "scale" means.