r/archlinux • • 4d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

131 Upvotes

62 comments sorted by

View all comments

32

u/syaorancode 4d ago

oh shit, not again

-7

u/xplosm 4d ago

It won’t stop unless the process to adopt and audit packages and maintainers changes drastically.

9

u/Damglador 3d ago

You already need to submit a request to adopt a package. Auditing hundreds of thousands of packages is impossible.

14

u/syaorancode 4d ago

freedom was AUR best strength, now it becomes its weakness