DARINORCold Lab
← All field notes

// FIELD NOTE — SUPPLY CHAIN

The attack does not exploit a bug in pacman, makepkg, or npm. It exploits the social and procedural trust that comes with an adopted package name.

From Atomic Arch: How 1,500 Orphaned Packages Became a Developer Credential Heist

This site uses minimal cookies and local storage to keep features like the chat widget and games working. We do not use third-party tracking cookies. Privacy Policy