ended6월 12일· 1 sources
수백 개 AUR 패키지가 정보 탈취 악성코드 공격을 받음
Why it matters
AUR's infection by malware disguised in 408 packages reveals how unverified open-source repositories can become distribution channels for credential theft attacks. The incident forces the industry to reconsider blind trust in community contributions and adopt trust models, code review requirements, and cooling-off periods before accepting package updates.
1
Sources
+0
24h
—
Growth
83d
Active
AURsupply chain attackmalware injectionnpm ecosystempackage verification