• jobbies@lemmy.zip
    link
    fedilink
    arrow-up
    20
    arrow-down
    1
    ·
    9 hours ago

    I’d love to know what’s going on with this. Arch has its haters but someone’s putting a lot of effort into this

    • brucethemoose@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      edit-2
      7 hours ago

      It seems like some person with a bot just asked to maintain a bunch of orphaned packages, abusing the 2-week waiting period. Right?

      Thats why they used npm; off the shelf, almost “standard practice” credential harvesting malware. Nothing too fancy.