1,500 compromised AUR packages expose supply chain gaps in cloud-native CI/CD. Learn SBOM, SLSA, and Sigstore defenses.

At least 1,500 malicious packages were published to the Arch User Repository (AUR) as part of the Atomic Arch supply chain attack.

Attackers hijacked over 1,500 packages in Arch Linux's AUR to plant a credential stealer. The official repos are safe, but the trust model took the hit.