
Attackers seized over 1,500 packages in the Arch User Repository by adopting orphaned packages and rewriting build instructions to install a credential stealer. No accounts were compromised. Arch froze new registrations while cleaning up. Official repos were unaffected.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
400+ Arch Linux AUR Packages Hijacked for Credential Stealer