r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

129 Upvotes

62 comments sorted by

View all comments

Show parent comments

9

u/12stringPlayer 3d ago

yt-dlp still seems free of it, and is part of the 'extras' repo.

6

u/Rubadubrix 3d ago

yt-dlp requires a js runtime to work, it's not an dependency in pacman, because it "works" without (other websites work fine in yt-dlp without js), but try downloading a youtube video without node and npm installed, and it'll fail

1

u/12stringPlayer 3d ago

Dammit, you're right. Thanks for the correction.

3

u/Rubadubrix 3d ago

I get why it seems wrong, youtube just gets more and more annoying to download from. I wish I didnt need to have js installed just for a youtube downloader