Malicious Atomic Arch NPM Campaign Thread
2026-06-14 02:29 UTC
Replies (3)
-
@brokenwing@discuss.tchncs.de 2026-06-14 03:11
Analyzing the commit history of libdata, you can see the attacker pushed the malicious PKGBUILD on Jun 11, 2026 14.59 GMT. And it was reverted back to the previous commit on the same day, about 2.5 hours later, on Jun 11, 2026 at 17:30 GMT. So it seems like if you updated the libgdata package during this period, your system might be affected.
-
@brucethemoose@lemmy.world 2026-06-14 03:17
Reposting this for visibility: github.com/lenucksi/aur-malware-check It analyzes your pacman install history, and some other things, for a more accurate check. Very useful.
-
@A_norny_mousse@piefed.zip 2026-06-14 06:48
https://bbs.archlinux.org/viewtopic.php?id=313892 This helped me get an overview yesterday. I made some comments, pointing out that some distros use the AUR in unintended ways, adding to its popularity but also making it easier for attackers to do shit like this. Today I was told that this was "politics" between distros and really everybody should be able to use the AUR how they see fit. That was a bit out there, but many people are hellbent on pushing the "company fucked up with tech security" narrative here.