I’m on the AUR mailing list and there has been huge influx of packages that were maliciously taken over today. Please check the PKGBUILD and be wary especially of new npm depencencies, particularly one named “atomic-lockfile”, but there might be others.
Yeah, it looked like a much smaller amount than what it actually was until recently. I have zero authority of speaking for Arch or the AUR. I just read mails and noticed and thought I tell my endeavourous friends over here.
Yeah another reason thy should add some kind of filter to auto scan files that being uploaded and does that are already in AUR and put all findings in a quarantine list for trusted people to review before being allowed in AUR.
Yeah, something like that is being discussed, but they also want to avoid multiplying the workload for the current admins/mods. And then there’s the question of who is a trusted user? How does one become a trusted user? BTW some of these packages have been overtaken by accounts using old usernames or realnames of their former owners.
Luckily the only thing I had that depends on npm was zed (which I never use). Uninstalled and a dummy npm file placed and chattr +i, so if I miss it it will not install.