Arch Linux disabled new account registration on the Arch User Repository after a wave of malicious commits. Over 1,500 user-submitted packages were compromised, with attackers pushing poisoned updates containing hostile JavaScript dependencies. The core Arch distribution remains unaffected.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
400+ Arch Linux AUR Packages Hijacked for Credential Stealer