• northernlights@fedia.io
    link
    fedilink
    arrow-up
    7
    ·
    2 days ago

    how did this happen? the linked thread show people identifying the infected packages and cleaning them up but no word about how it happened or how to prevent it.

    • rozodru@piefed.world
      link
      fedilink
      English
      arrow-up
      25
      ·
      2 days ago

      I think it was essentially orphaned stuff that got “picked up” by a “new maintainer” and that’s how it happened.

        • Telorand@reddthat.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 days ago

          You’re only affected if you use the AUR. As far as I understand it, the core packages themselves are fine, so this is more of a MitM attack, where somebody compromised the package download streams