Attackers hijacked 400+ Arch Linux AUR packages to run a Rust credential stealer, with optional eBPF rootkit support on root ...
AUR was considered a looming security threat.
I've run Arch nine different ways, BTW.
Malicious apps got into the Arch User Repository - how to protect yourself ...
Arch Linux defends itself against a wave of attacks that have massively contaminated package descriptions in the unofficial Arch User Repository with malware.