The worst part about this is it's not a compromised supply chain, this is the AUR working as intended. The AUR is from a time of open APIs and FTP servers, so if a package has no maintainer, anyone even a brand new account can adopt it and push changes.
Mas de 400 paquetes AUR (no los de arch Linux oficial, ni los repositorios de AUR) han sido comprometidos
yo uso unos cuantos pero no se si tendran malware si alguien sabe como puedo averiguar si estoy infectado me seria de ayuda
More than 400 packages in the Arch User Repository (AUR) have been found to contain malware in a major supply chain attack.
According to security researchers at Sonatype, attackers took over abandoned AUR packages by posing as trusted maintainers.
They modified the packages to download a malicious npm dependency called atomic-lockfile, which contained code designed to steal information and maintain access to infected systems.
Arch Linux’s official repositories were not affected. The attack impacted only the AUR, a community-maintained collection of package build scripts.
Arch maintainers have removed the malicious packages and blocked the accounts involved. The number of affected packages grew to more than 400 before the campaign was discovered.
Sources: Sonatype researchers and Arch Linux community reports.
@Pirat_Nation Están asustados por que los obligaría a dejar de vender una licencia y volverlo un producto
aunque me gustaría saber si la iniciativa tiene soluciones para cualquier duda de las empresas
@idontwanadie esto no aporta nada por que hay 2 hentais y automáticamente deberíamos haberlo entendido desde el principio
por cierto el del medio es peak