• LeFantome@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    1 month ago

    It is a well known risk but not something that was a real risk numerically. I mean, it still isn’t given the number of packages in the AUR.

    This is a couple of malicious packages discovered in a short period though. Not a good sign.

    You should always inspect AUR packages before installing them but few people do. Many would not even know what they were looking at.