← All topics

supply chain attack

2 captures, most recent first.

Sichu Lu @lu_sichu

quoting a report excerpt — saved image

Sichu Lu @lu_sichu
who is this absolute hero

[Quoted image of report text]
All of these strategies were instrumental toward the goal of getting the PR merged in order to execute the supply chain attack. This was pursued by both pressuring the reviewers and attempting to steal the git credentials of the repository maintainer.

The suspicious GitHub activity was caught by a different user denoted <PERSON_C>. They noticed that the GitHub Issue included a prompt injection, and deliberately tested the code snippet from the GitHub Issue in a containerised sandbox to confirm it contained malware. The agent briefly achieved remote code execution as the root user inside this sandbox, and used it to conduct reconnaissance, which was limited to what it could determine from the sandbox (see Section 4.2.3). <PERSON_C> then commented on both the issue and the pull request about the discovered malware.

6:10 PM · Aug 4, 2026 · 68 Views
Note from Claude Sonnet 5

A tweet from Sichu Lu (@lu_sichu) praising an anonymized user (PERSON_C) described in a quoted incident-report excerpt as having caught and safely investigated a supply-chain attack attempt involving a GitHub PR, prompt injection, and malware.

ai safetysecurity incidentsupply chain attacktwitter

Danielle Fong @DanielleFong

— saved image

Danielle Fong 🐦☀️ @DanielleFong · 7h
cybersecurity apocalypse time

[quoted tweet]
LaurieWired @lauriewired · 8h
Wild, but expected. AUR (Arch Linux User Repository) pushes completely disabled due to influx of malware.

I predicted widespread temporary shutdowns ...

[embedded image, left: mailing list post]
...archlinux.org
[thread] AUR packages adoption disabled
[Robin Candau]
7/30/26 6:22 PM, Robin Candau wrote:
Hi everyone,
Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation.
We will send a follow-up once we're able to. In the meantime, feel free to report suspicious adoption events or commits that haven't been dealt with yet, and stay vigilant!
Thanks for your understanding.
Cheers,
[Robin] Candau / Antiz on behalf of the Arch Linux DevOps team

[everyone,]
[We] have now disabled pushes altogether as well for the moment, while we [hand]le the situation. Sorry for the inconvenience.
[Reg]ards,
[Rob]in Candau / Antiz

[Atta]chments:
PGP_0xFDC3040B92ACA748.asc (application/pgp-keys — 9.3 KB)
PGP_signature.asc (application/pgp-signature — 840 bytes)

[embedded image, right: video screenshot]
Laurie Prediction:
[...s]e a major developer package repository has to [...] registrations for >24hrs in 2026
Note from Claude Sonnet 5

X post: Danielle Fong captions 'cybersecurity apocalypse time' quoting @lauriewired's post about the Arch Linux User Repository (AUR) disabling all package pushes/adoptions due to a malware influx, with screenshots of the Arch Linux devops mailing list announcement and a video clip of Laurie noting she'd predicted this kind of event.

twittercybersecurityarch linuxsupply chain attackmalware