

34·
2 months agolemmy loop you in: https://infosec.exchange/@ifin/116735279416101129
TL;DR; lots of aur packages got hijacked and install a infostealer, if you updated today/yday, there is a reasonable chance you got hit by it :(
also: the info stealer is installed by aur via npm
the article makes some good points on why not though, also they offer anyone that wants to help to first ask them.
in the end its “their” property that you’re trying to fix, with them responsible for it when you do it wrong