Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) after security teams detected a wave of malicious takeovers and follow-up commits designed to compromise unsuspecting users. The move, announced by Robin Candau (known online as Antiz) on behalf of the Arch Linux DevOps team, comes as attackers increasingly exploit an abandoned or unmaintained package as an entry point for supply-chain attacks. Last month, a massive supply chain attack targeting the Arch User Repository (AUR) compromised more than 400 community-maintained packages, with attackers injecting malicious build scripts designed to deploy credential-stealing malware and rootkit-style payloads on affected Linux systems. The AUR is a...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!