Remix.run Logo
Over 900 Arch Linux Packages Infected with infostealers and rootkits(lists.archlinux.org)
20 points by fortran77 a day ago | 3 comments
mdlxxv a day ago | parent | next [-]

Very misleading title. AUR "recipes" are NOT official Arch Linux packages. Basically anyone can upload stuff to the AUR. Users are expected to read and understand the AUR PKGBUILDs before trying to build them.

tiberious726 19 hours ago | parent [-]

"Over 900 packages infected in a repository anyone can upload to, it just has to be compatible with Arch"

WalterGR 21 hours ago | parent | prev [-]

https://news.ycombinator.com/item?id=48500447

“AUR packages compromised with Infostealer and Rootkit” (ifin.network)

257 points | 15 hours ago | 189 comments