deathmetal27@lemmy.world to linuxmemes@lemmy.world · 4 days agoAvoid this very common mistakelemmy.worldimagemessage-square73linkfedilinkarrow-up1396arrow-down110file-text
arrow-up1386arrow-down1imageAvoid this very common mistakelemmy.worlddeathmetal27@lemmy.world to linuxmemes@lemmy.world · 4 days agomessage-square73linkfedilinkfile-text
Transcript Image of a man pointing a gun at his own foot. Caption: Installing an AUR package without reading it’s PKGBUILD.
minus-squareMonkderVierte@lemmy.ziplinkfedilinkarrow-up9·4 days agoAll pointing with fingers to AUR, but the issue was (yet again) with NPM.
minus-squarechortle_tortle@mander.xyzlinkfedilinkarrow-up4·4 days agoSorry I missed something, how so?
minus-squareMonkderVierte@lemmy.ziplinkfedilinkarrow-up6·4 days agoThe compromised packages load a script from thr net that runs a compromised npm package (“atomic-lockfile” 1.4.2). Ok, also a AUR issue. But more so a NPM one, since they have all full moon two supply-chain attacks.
All pointing with fingers to AUR, but the issue was (yet again) with NPM.
Sorry I missed something, how so?
The compromised packages load a script from thr net that runs a compromised npm package (“atomic-lockfile” 1.4.2).
Ok, also a AUR issue. But more so a NPM one, since they have all full moon two supply-chain attacks.