deathmetal27@lemmy.world to linuxmemes@lemmy.world · 2 days agoAvoid this very common mistakelemmy.worldimagemessage-square67linkfedilinkarrow-up1370arrow-down18file-text
arrow-up1362arrow-down1imageAvoid this very common mistakelemmy.worlddeathmetal27@lemmy.world to linuxmemes@lemmy.world · 2 days agomessage-square67linkfedilinkfile-text
Transcript Image of a man pointing a gun at his own foot. Caption: Installing an AUR package without reading it’s PKGBUILD.
minus-squareMonkderVierte@lemmy.ziplinkfedilinkarrow-up9·2 days agoAll pointing with fingers to AUR, but the issue was (yet again) with NPM.
minus-squarechortle_tortle@mander.xyzlinkfedilinkarrow-up4·2 days agoSorry I missed something, how so?
minus-squareMonkderVierte@lemmy.ziplinkfedilinkarrow-up6·2 days agoThe compromised packages load a script from thr net that runs a compromised npm package (“atomic-lockfile” 1.4.2). Ok, also a AUR issue. But more so a NPM one, since they have all full moon two supply-chain attacks.
All pointing with fingers to AUR, but the issue was (yet again) with NPM.
Sorry I missed something, how so?
The compromised packages load a script from thr net that runs a compromised npm package (“atomic-lockfile” 1.4.2).
Ok, also a AUR issue. But more so a NPM one, since they have all full moon two supply-chain attacks.