• LeFantome@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      1 month ago

      It is a well known risk but not something that was a real risk numerically. I mean, it still isn’t given the number of packages in the AUR.

      This is a couple of malicious packages discovered in a short period though. Not a good sign.

      You should always inspect AUR packages before installing them but few people do. Many would not even know what they were looking at.