Well...
maybe it's not quite apocalypse, but it's damned serious.
Every
user of Arch and Linux distributions based on it (CachyOS,
Manjaro, Endeavour, etc) needs to know that a major
poisoning of the AUR (Arch User Repository) has taken place.
At the time I ran a script yesterday to determine if my
system had been infected (it wasn't), 1,617 AUR packages had
been identified as "updated" with versions containing
credential snatchers.
(To
people not using Arch, the AUR is roughly analogous to
Ubuntu PPAs and Fedora RPM Fusion. It is a location for
user-maintained packages that are not part of the official
vetted repository. The AUR currently lists more than 114,000
packages.
The
attacker(s) identified packages that were being used but no
longer maintained, exploiting existing AUR policy to request
and gain maintainer access. No hacking or policy-breaking
was done.