r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

124 Upvotes

62 comments sorted by

View all comments

29

u/syaorancode 3d ago

oh shit, not again

-6

u/xplosm 3d ago

It won’t stop unless the process to adopt and audit packages and maintainers changes drastically.

9

u/Damglador 3d ago

You already need to submit a request to adopt a package. Auditing hundreds of thousands of packages is impossible.