Sonatype researchers discovered roughly 1,500 malicious packages in the Arch User Repository. The AUR allows anyone to upload packages, and volunteer Trusted Users review submissions. The Arch team urged users to review all PKGBUILD and install script changes when updating and to report suspicious commits.
Tap to vote and see what everyone thinks.
Summary by ByteBrief