A massive supply chain attack targeting the Arch User Repository (AUR) has compromised more than 400 community-maintained packages, with attackers injecting malicious build scripts designed to deploy credential-stealing malware and rootkit-style payloads on affected Linux systems.
I just checked the new list with 1937 infected packages, not a single match. Again, am I just lucky or are all these 1937 packages barely used by people?