this post was submitted on 29 Mar 2024
1 points (100.0% liked)

Arch Linux

7744 readers
1 users here now

The beloved lightweight distro

founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 0 points 7 months ago (1 children)

This is just speculation, but I think this was a long planned attack. I think it's unlikely any previous backdoors or significant security vulnerabilities would have been introduced, the goal was to establish themselves as a legitimate contributor and then sneak one critical backdoor in unnoticed. Sneaking in multiple vulnerabilities would have increased the risk of detection.

From what I understand they did cause a conflict with another package, and then used that to try to justify having the backdoored versions of the package fast tracked into upcoming Debian and fedora releases. But that would also suggest that their whole goal was shipping this one backdoor.

[–] [email protected] 0 points 7 months ago* (last edited 7 months ago) (1 children)
[–] [email protected] 0 points 7 months ago

Well that's unfortunate