Probably a interesting read. Adding it the list of things I don't have time to read....
Archive: https://archive.today/fMgxh
From the post:
>Malicious attacks on open source software packages are a growing concern. This concern morphed into a panic-inducing crisis after the revelation of the XZ Utils backdoor, which would have provided the attacker with, according to one observer, a "skeleton key" to the internet. This study therefore explores the challenges of preventing and detecting malware in Linux distribution package repositories.
Probably a interesting read. Adding it the list of things I don't have time to read....
Archive: https://archive.today/fMgxh
From the post:
>>Malicious attacks on open source software packages are a growing concern. This concern morphed into a panic-inducing crisis after the revelation of the XZ Utils backdoor, which would have provided the attacker with, according to one observer, a "skeleton key" to the internet. This study therefore explores the challenges of preventing and detecting malware in Linux distribution package repositories.