Update: the AUR compromise appears to be ongoing
After the initial incident affecting 1,500+ packages, another wave of malicious AUR packages has been discovered. This time the attackers reportedly used code obfuscation to better conceal the malicious behavior.
Affected packages included Node.js packages, Firefox-related packages, LibreWolf extensions, NeoVim plugins and others.
If you’re using #Arch Linux and install software from AUR, I’d review recently updated packages and keep an eye on this story.
https://t.co/4eD3Ola9DH