Thinking of leaving Manjaro after the AUR supply chain attack – Distrochooser recommends SUSE, what's your take? (opens in new tab)
submitted by atomic-lockfile, which deployed credential-stealing malware and even eBPF rootkits. The fact that the trusted packages themselves didn’t look malicious makes this especially concerning. Like many Arch users, I’ll admit I don’t carefully read every PKGBUILD before installing from the AUR. The official recommendation has always been to review them manually, but realistically, who does that for every package? This incident made me realize I’ve been relying on trust rather than vigil...
Read the original article