this post was submitted on 12 Jun 2026
98 points (99.0% liked)

Linux

17876 readers
34 users here now

Welcome to c/linux!

Welcome to our thriving Linux community! Whether you're a seasoned Linux enthusiast or just starting your journey, we're excited to have you here. Explore, learn, and collaborate with like-minded individuals who share a passion for open-source software and the endless possibilities it offers. Together, let's dive into the world of Linux and embrace the power of freedom, customization, and innovation. Enjoy your stay and feel free to join the vibrant discussions that await you!

Rules:

  1. Stay on topic: Posts and discussions should be related to Linux, open source software, and related technologies.

  2. Be respectful: Treat fellow community members with respect and courtesy.

  3. Quality over quantity: Share informative and thought-provoking content.

  4. No spam or self-promotion: Avoid excessive self-promotion or spamming.

  5. No NSFW adult content

  6. Follow general lemmy guidelines.

founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] zurchpet@lemmy.ml 5 points 1 week ago (2 children)

So 0.28% of the 140'000 packages?

Seems like not that much.

How many malicious packages are on Googles Play Store?

[–] teft@piefed.social 31 points 1 week ago* (last edited 1 week ago)

I agree that that isn’t a lot of packages but it matters more which packages were compromised. Some random package like ten people have installed? Who cares. yay or spotify? We might have some problems.

Edit: after looking at the list some look fairly concerning. I’d definitely be doing a diff on my packages and the list of the compromised packages if i used Arch, btw.

[–] Zachariah@lemmy.world 7 points 1 week ago

unfortunately for some, it’s 100% of the 400 packages they use