Live data from Hacker News

Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories

blog.nietaanraken.nl

1–3 of 3 posts

Re: Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories

#3
post #2

Should note this only applies to AUR packages and `-git` mostly because of missing archive hashes. AUR packages pinned to mutable tags are easiest to hijack.

article notes that they "found nine vulnerable packages (in the community repository)"