• eleefece@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 hours ago

    Could the same thing happen on Flathub? Considering the number of unverified packages on the platform

    • Bizzle@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 hours ago

      My understanding is that flatpaks run in a sandbox, so although there is a risk- especially for what you give permissions to- it’s not exactly the same. The AUR is basically “curl | bash”, it’s a miracle this hasn’t happened before. If you’re worried about it I think flatseal can look at the permissions and such, but you’re probably fine.

  • mecen@lemmy.ca
    link
    fedilink
    arrow-up
    0
    ·
    13 hours ago

    Well these accounts are probably making first commit so it can also be easily found

    • bobo@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      12 hours ago

      Alternatively, the first wave of malware stole the accounts of actual contributors. The same method was used in npm afaik.