Remix.run Logo
mewpmewp2 5 hours ago

How would they create that noise?

xg15 4 hours ago | parent [-]

Depends on the level of infiltration I guess. If the attacker managed to get themselves into a trusted position, as with the XZ backdoor, they could use the official communication channels of the project and possibility even file a CVE.

If it's "only" technical access, it would probably be harder.

andix 4 hours ago | parent [-]

If they file a CVE, they will draw a lot of attention from experts to the project. Even from people who never heard from this package before.