Are there actually any clues as to who the attackers are?

And aside from the attackers, what should one think of those who profit
from this?

I may be wrong, but are these people profiting from this? See:

"Sonatype researchers have identified a malicious package campaign,
dubbed Atomic Arch, that targets orphaned packages in the Arch User
Repository (AUR)." -
https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency

Actually Arch Linux users and AUR maintainers noticed the attacks.

I don't want to accuse anyone here of being responsible for the attacks,
but exploiting the attacks, which have harmed a significant portion of
the open-source community, namely us, for promotional purposes is also
reprehensible.

Am I misunderstanding this? English isn't my native language, did I
perhaps translate it too literally?

Reply via email to