340
400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers
(cybersecuritynews.com)
This is a most excellent place for technology news and articles.
I don't understand this argument. Isn't it better to build once and distribute binaries than to make everyone compile it themselves? The vast majority of AUR packages I use are -bin versions.
You don't get to see the code that way, which is where bad actors thrive. Also it wasn't compiled for exactly your system.