▲ 448 ▼ 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers (cybersecuritynews.com) submitted 3 months ago by rafssunny@lemmy.zip to c/technology@lemmy.world 144 comments fedilink hide all child comments
[–] gemakey@lemmy.world 6 points 3 months ago (7 children) Holy shit it's like all of Python. permalink fedilink source parent hideshow 7 child comments replies: [–] Eldritch@piefed.world 7 points 3 months ago (1 child) Yeah, Python has been a massive vulnerability for a long while. And the AUR has similar issues. This is only getting widespread coverage now. But it's always been a risk. permalink fedilink source parent hideshow 1 child comment replies: [–] HaraldvonBlauzahn@feddit.org 1 point 3 months ago Yes, we need a kind of Debian for Python. Part of the solution could be the Guix package manager. Part could be the commercial offerings, like Anaconda. permalink fedilink source parent [–] CaptDust@sh.itjust.works 2 points 3 months ago (3 children) Well, those are mostly extension libraries, stuff "normally" installed using pip. Arch is kind of unique that they encourage using system aur over pip, npm and other package managers. While it is a big radius, none of the python packages stick out to me, but maybe I just haven't encountered the popular ones. permalink fedilink source parent hideshow 3 child comments replies: [–] iocase@lemmy.zip 5 points 3 months ago The attackers specifically targeted orphaned projects on AUR so it's no wonder most of those aren't familiar to us. permalink fedilink source parent [–] esc@piefed.social 3 points 3 months ago (1 child) It isn't really all that unique? Debian does it, el does it, probably almost any popular distro? permalink fedilink source parent hideshow 1 child comment replies: [–] CaptDust@sh.itjust.works 1 point 3 months ago I suppose it's become more common since PEP 668 was introduced, less unique these days. permalink fedilink source parent [–] flying_sheep@lemmy.ml 2 points 3 months ago Arch usually doesn't re-package Python packages that aren't needed for something else, meaning they end up in the AUR. I maintain several there, and when I stop using them I abandon them. I wouldn't be surprised if some of the ones I used to maintain are on the list permalink fedilink source parent
[–] Eldritch@piefed.world 7 points 3 months ago (1 child) Yeah, Python has been a massive vulnerability for a long while. And the AUR has similar issues. This is only getting widespread coverage now. But it's always been a risk. permalink fedilink source parent hideshow 1 child comment replies: [–] HaraldvonBlauzahn@feddit.org 1 point 3 months ago Yes, we need a kind of Debian for Python. Part of the solution could be the Guix package manager. Part could be the commercial offerings, like Anaconda. permalink fedilink source parent
[–] HaraldvonBlauzahn@feddit.org 1 point 3 months ago Yes, we need a kind of Debian for Python. Part of the solution could be the Guix package manager. Part could be the commercial offerings, like Anaconda. permalink fedilink source parent
[–] CaptDust@sh.itjust.works 2 points 3 months ago (3 children) Well, those are mostly extension libraries, stuff "normally" installed using pip. Arch is kind of unique that they encourage using system aur over pip, npm and other package managers. While it is a big radius, none of the python packages stick out to me, but maybe I just haven't encountered the popular ones. permalink fedilink source parent hideshow 3 child comments replies: [–] iocase@lemmy.zip 5 points 3 months ago The attackers specifically targeted orphaned projects on AUR so it's no wonder most of those aren't familiar to us. permalink fedilink source parent [–] esc@piefed.social 3 points 3 months ago (1 child) It isn't really all that unique? Debian does it, el does it, probably almost any popular distro? permalink fedilink source parent hideshow 1 child comment replies: [–] CaptDust@sh.itjust.works 1 point 3 months ago I suppose it's become more common since PEP 668 was introduced, less unique these days. permalink fedilink source parent
[–] iocase@lemmy.zip 5 points 3 months ago The attackers specifically targeted orphaned projects on AUR so it's no wonder most of those aren't familiar to us. permalink fedilink source parent
[–] esc@piefed.social 3 points 3 months ago (1 child) It isn't really all that unique? Debian does it, el does it, probably almost any popular distro? permalink fedilink source parent hideshow 1 child comment replies: [–] CaptDust@sh.itjust.works 1 point 3 months ago I suppose it's become more common since PEP 668 was introduced, less unique these days. permalink fedilink source parent
[–] CaptDust@sh.itjust.works 1 point 3 months ago I suppose it's become more common since PEP 668 was introduced, less unique these days. permalink fedilink source parent
[–] flying_sheep@lemmy.ml 2 points 3 months ago Arch usually doesn't re-package Python packages that aren't needed for something else, meaning they end up in the AUR. I maintain several there, and when I stop using them I abandon them. I wouldn't be surprised if some of the ones I used to maintain are on the list permalink fedilink source parent