The Arch User Repository discovered that malicious accounts injected malware into more than 400 software packages. The security incident involves compromised submissions that add the NPM package manager to install keyloggers or information stealers when users download affected applications.
Maintainers delete malicious commits instead of removing entire software packages from the community repository.
Arch Linux maintainers are responding by actively resetting and deleting the malicious commits instead of removing the entire packages from the repository. Jonathan Grotelüschen, a junior package maintainer, stated in the discussion thread that the maintenance team is working hard to reset or delete all malicious commits and ban the involved accounts.
Users running Arch Linux distributions should pause updates until the purge process finishes completely. The maintainers are prioritizing the removal of injected code over deleting the compromised packages themselves.
The incident targets the Arch User Repository, a community-driven collection of software packages for the Arch Linux distribution. The incident underscores persistent security vulnerabilities in community-driven software repositories that depend on rigorous review processes to prevent malicious code injection.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.