Recently heard that on June 11th, the AUR got attacked by this malware, dubbed "Atomic Arch" Apparently it uses orphaned AUR packages to inject an NPM install snippet to install their own rootkit/credential harvesting JS, using npm install atomic-lockfile minimist chalk and a dependency [email protected]. I use EndeavourOS, any other Linux users that happen to use an Arch-based distro? I haven't really been on Linux for the past four days, so I am not gonna update for a while and stick to my Windows dualboot for now It is also rootkit-like in the terms of behavior and persistence and has infected around 1,500 packages Hope everyone stays safe!
So far I'm safe. checked and no signs of the malware the only time I'm updating is when it all fades out and the AUR team actually cleans this whole mess up. I don't even have npm installed so the rootkit cannot install itself anyway