Transcript

Image of a man pointing a gun at his own foot.

Caption: Installing an AUR package without reading it’s PKGBUILD.

  • MonkderVierte@lemmy.zip
    link
    fedilink
    arrow-up
    4
    ·
    7 hours ago

    The compromised packages load a script from thr net that runs a compromised npm package (“atomic-lockfile” 1.4.2).

    Ok, also a AUR issue. But more so a NPM one, since they have all full moon two supply-chain attacks.