On 10/9/26 11:15 AM, Robin Candau wrote:
On 10/9/26 11:12 AM, DodoGTA GT wrote:
All of the ixnewton's github repos have commits pushed with message
"Add security audit workflow" 12 hours ago

Maybe the user got targeted by some limited scope credential/session
theft and didn't
notice that happened (because they were sitting in their Devin environment)?

Yes, most likely. I will contact the maintainer to ensure they know.


For info, I exchanged with the maintainer who now cleaned-up every affected GitHub repository (see e.g. https://github.com/ixnewton/org.kde.plasma.quicklaunch/commit/4eb5620b007322749b7a50c42514a710a109f03c) and took some hardening actions.

I'm coordinating with them to restore the packages on the AUR (which were not affected by the malicious upstream file, just to make things clear).

--
Regards,
Robin Candau / Antiz

Attachment: OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to