On 10/9/26 11:15 AM, Robin Candau wrote:
On 10/9/26 11:12 AM, DodoGTA GT wrote:All of the ixnewton's github repos have commits pushed with message"Add security audit workflow" 12 hours agoMaybe the user got targeted by some limited scope credential/session theft and didn'tnotice that happened (because they were sitting in their Devin environment)?Yes, most likely. I will contact the maintainer to ensure they know.
For info, I exchanged with the maintainer who now cleaned-up every affected GitHub repository (see e.g. https://github.com/ixnewton/org.kde.plasma.quicklaunch/commit/4eb5620b007322749b7a50c42514a710a109f03c) and took some hardening actions.
I'm coordinating with them to restore the packages on the AUR (which were not affected by the malicious upstream file, just to make things clear).
-- Regards, Robin Candau / Antiz
OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
