• RustyNova@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    9 hours ago

    The AUR attack attacked the build files. On nix, you could easily set a new download url for the package, set the new hash, and claim the project has moved to a new repo/site.

    That would require a second person to vet on it, but it could be seen as normal for a maintainer not in the know about the project.

    New packages are harder to pass, but it could also work.