20 pointsby fortran7711 hours ago2 comments
  • mdlxxv11 hours ago
    Very misleading title. AUR "recipes" are NOT official Arch Linux packages. Basically anyone can upload stuff to the AUR. Users are expected to read and understand the AUR PKGBUILDs before trying to build them.
    • tiberious7267 hours ago
      "Over 900 packages infected in a repository anyone can upload to, it just has to be compatible with Arch"
  • WalterGR8 hours ago
    https://news.ycombinator.com/item?id=48500447

    “AUR packages compromised with Infostealer and Rootkit” (ifin.network)

    257 points | 15 hours ago | 189 comments