More than 1.500 packages added by users to the Arch Linux User Repository “AUR” were found to be infected with malware.
As of yesterday, Arch Linux maintainers have been working to restore/delete all malicious content and ban the accounts that uploaded the malware. Over 400 packages are believed to have been affected by this latest attack on the Arch Linux AUR. To be clear, this only affects AUR packages, not official Arch Linux packages.
In an update a few hours ago, Arch Linux maintainers believe that around 900 packages were infected with malware in this week's incident.
I should mention that since yesterday I reinstalled the Fedora distribution (44), as I have been using Arch Linux with some AUR packages lately.
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.

