138
Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Halted
(www.phoronix.com)
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
No way to prevent this, says only repo where this regularly happens
I mean, nobody is saying there is no way to prevent this, and I would hardly say that "twice" can be cathegorized as regularly.
Also I find this of extremely bad taste as you seem to compare this to school shootings, with literal children deaths. I would say that a few thinkerers getting pwned from their claude tokens is a couple orders of magnitude less serious.
Not the only repo, see: npm
Npm doesn't let you easily take over packages you don't own.
but does let you take over their maintainers' accounts (through poor security) and easily poison them
Not more easily than anything else.
Besides all the other non infected ways to install the software, there is a way to prevent this: Just read the AUR package before install and don't trust blindly any new maintainer.
It's metaphysical approach to security. Enshrined rules that can't be enforced don't define user's behavior.
Isn't this similar to the reason a lot of people hate snaps? Or am I misunderstanding something? I'm not an Arch user (btw) so I'm not sure familiar with AUR.
Some of the hate for snaps is because it's Cannonical trying to use its install base (Ubuntu) to push a particular format on the entire community as a vector for control
You're right on malware finding its way onto the Snap Store. I find it hilarious to see that the employed tactics are basically identical 😜.
However, FYI, the hate on Snaps is a lot more broad than that.