

People using the aur on steamOS probably are doing so through distrobox. Distrobox doesn’t sandbox as far as I know, so the infostealer part of the malware would still be a risk. The rootkit part I’m guessing would fail, since I think distrobox on Deck usually runs in rootless mode.
It also seems like there was a fairly short window of time before the infected packages were caught, anyone who didn’t update one of the compromised packages on that exact day should be fine.







Pretty scary, my desktop had the libgdata package left over as an orphan from something I had installed in the past. Thankfully I hadn’t updated on the day of the attack, my package logs show my build of libgdata was from a February update instead.