Arch Linux AUR Hit by Sophisticated Malware Wave

Arch Linux’s User Repository (AUR) is facing a second, more stealthy wave of malware attacks immediately after a massive purge of 1,500 infected packages. The new campaign employs obfuscated code to evade detection, targeting Node.js packages, Firefox extensions, and NeoVim plugins, prompting calls for the repository to be made read-only to prevent further infections.