With all the supply chain attacks in the Linux ecosystem, isn’t the natural solution to move to full application sandboxing?

Flatpacking is great but not all applications support it.

Is it too much of a hassle?

  • FineCoatMummy@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    19 hours ago

    The latest attack on the AUR

    For anyone else like me who was OOTL, I guess that refers to this…

    https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html

    If a flagged package ran, treat the host as credential-compromised. Rotate everything the stealer touches: browser sessions, SSH keys, GitHub and npm tokens, Slack, Teams and Discord sessions, Vault tokens, Docker and Podman credentials, and any cloud keys.

    If the package ran as root, assume the rootkit is present and reinstall from trusted media. There is no way to trust the system otherwise.

    Jeepers!