Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Zalasur 🐸🇺🇦
@zalasur@mastodon.surazal.net  ·  activity timestamp 6 days ago

The #ArchLinux AUR malware attack is a type of supply chain attack not unlike the more widely publicized and widespread NPM ones. In this case "orphaned" projects were claimed by a malicious actor and had info-stealing code placed in the pre-install scripts for those projects. The simple act of installing them would compromise your system.

The original post does not allow quote boosting, but here's the link to it. It provides the most comprehensive account I've seen.

https://gaysex.cloud/notes/andaxow7itfn05x9

  • Copy link
  • Flag this post
  • Block
Log in Create account

Bolhaverso

Os dados dos usuários serão deletados em algumas semanas. Vamos subir uma instância definitiva após finalizar os testes.

Bolhaverso: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login Signup