Hundreds of orphaned Arch User Repository (AUR) packages have been compromised by an attacker who injected a malicious npm package called 'atomic-lockfile' capable of exfiltrating sensitive data. The Arch Linux project is actively cleaning up the affected packages. A list of compromised packages is available, and users of Arch Linux or Arch-based distributions who use AUR packages are advised to check whether they have installed any of the affected updates.
338 Impressions