A coordinated supply chain attack was discovered in the Arch User Repository (AUR), where approximately 408 packages had malicious commits injecting `npm install atomic-lockfile` commands into their PKGBUILDs or related install/hook scripts. A community member identified the full list of affected packages by scanning the AUR's GitHub mirror. The AUR team is actively resetting/deleting the malicious commits and banning the responsible accounts, while contributors are asked to report additional affected packages in a single email thread.

15m read timeFrom lists.archlinux.org
Post cover image
23K Impressions1 Comment