I wonder how many Arch users are bragging about using Arch today
The Arch Linux AUR had over 400 packages compromised with malware
#Arch #Linux #AUR #Packages #Compromised #Malware #Security #Vulnerability #OpenSource #Tech
AUR Packages Compromised with Infostealer and Rootkit
https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
#HackerNews #AUR #Packages #Compromised #Infostealer #Rootkit #Cybersecurity #Vulnerabilities

Last Updated: 2026-06-12T04:22:42Z (UTC) What’s Happening It appears an AUR package maintainer’s account (arojas) was compromised. The maintainer’s account had write access to over 400 package repos. The compromise was reported and other AUR maintainers have been working to remove the infected packages. The affected packages were modified with preinstall scripts to use npm to install the atomic-lockfile package, a malicious payload. Here’s an example of the change: This blog has a deep d...
For the 2nd time in weeks, #Microsoft packages laced with #credential stealer
Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.
In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
#security
#appleintelligence changing your #compromised #passwords for you _seems_ like a good idea, but what happens after it changes your passwords for like 20 sites and you then loose your iPhone?
Dozens of #RedHat packages #backdoored through its official #NPM channel
Official Red Hat NPM accounts have been #compromised and used to push a malicious #worm that spreads from machine to machine, where it pilfers sensitive credentials in hopes of stealing yet more confidential data, researchers said.
#privacy #security