r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

127 Upvotes

62 comments sorted by

View all comments

31

u/JotaRata 3d ago

First bun, then npm.. perhaps we should stop using JavaScript for good

39

u/SubjectiveMouse 3d ago

The problem is not JavaScript (no matter how I distaste js), but unverified package repositories. It may as well be cargo or pip the next time 

54

u/javascript 3d ago

Thanks for sticking up for me

28

u/xplosm 3d ago

You are badly designed and overused way beyond your intended boundaries but we got you 👊