logoalt Hacker News

Arch Linux AUR Hit by Another Wave of Now More Sophisticated Malware Attack

39 pointsby ImJamaltoday at 1:30 PM8 commentsview on HN

Comments

Shanktoday at 2:40 PM

Is there any information on if this is the same attack vector (orphaned packages that were adopted)? I believe they already locked down adoption, but maybe also a combination of existing maintainers being taken over?

show 1 reply
7etoday at 2:29 PM

Companies like Anthropic and OpenAI need to sponsor open source projects by giving them free agent credits. Otherwise, bad actors can just outspend and totally overwhelm the somewhat dim and very overworked set of human maintainers. Humans in software are obsolete, full stop.

show 1 reply