Transcript

Image of a man pointing a gun at his own foot.

Caption: Installing an AUR package without reading it’s PKGBUILD.

    • MonkderVierte@lemmy.zip
      link
      fedilink
      arrow-up
      4
      ·
      7 hours ago

      The compromised packages load a script from thr net that runs a compromised npm package (“atomic-lockfile” 1.4.2).

      Ok, also a AUR issue. But more so a NPM one, since they have all full moon two supply-chain attacks.