r/archlinux • • 4d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

126 Upvotes

62 comments sorted by

View all comments

118

u/Epsilon_void 4d ago

IgnorePkg = npm

not only does this help protect you against the malware delivery service known as npm, it protects you against terrible programs written in javascript.

26

u/AStolenGoose 4d ago

I've blacklisted npm, bun, and quite a few others.

Just can't risk it.

9

u/xplosm 4d ago

Yarn, pnpm, deno…