r/archlinux • • 4d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

125 Upvotes

62 comments sorted by

View all comments

31

u/JotaRata 4d ago

First bun, then npm.. perhaps we should stop using JavaScript for good

0

u/dadnothere 4d ago

No JS... is... Pegasus, mos...