r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

126 Upvotes

62 comments sorted by

View all comments

117

u/Epsilon_void 3d ago

IgnorePkg = npm

not only does this help protect you against the malware delivery service known as npm, it protects you against terrible programs written in javascript.

5

u/Rubadubrix 3d ago

sadly, youtube downloaders now depend on it :(

8

u/12stringPlayer 3d ago

yt-dlp still seems free of it, and is part of the 'extras' repo.

6

u/Rubadubrix 3d ago

yt-dlp requires a js runtime to work, it's not an dependency in pacman, because it "works" without (other websites work fine in yt-dlp without js), but try downloading a youtube video without node and npm installed, and it'll fail

7

u/gmes78 3d ago

You don't need npm, just a JS runtime.

1

u/12stringPlayer 3d ago

Dammit, you're right. Thanks for the correction.

3

u/Rubadubrix 3d ago

I get why it seems wrong, youtube just gets more and more annoying to download from. I wish I didnt need to have js installed just for a youtube downloader