438
400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers
(cybersecuritynews.com)
This is a most excellent place for technology news and articles.
I only ever access the AUR in an Arch distrobox... The containerization should protect me right?
Absolutely not
Nope. Distrobox does not offer any meaningful protection, since its purpose is to integrate with the system. It's basically meant to make downloading and managing packages from different distros, on the same system, much easier... but it's not meant to protect and isolate your device the same way that Flatpak or other type of containers do. That baing said, stop relying on Distrobox as a safety measure, and check your recently installed and updated packages since 9th June, to make sure you were not infected.