Are there actually any clues as to who the attackers are? And aside from the attackers, what should one think of those who profit from this?
I may be wrong, but are these people profiting from this? See: "Sonatype researchers have identified a malicious package campaign, dubbed Atomic Arch, that targets orphaned packages in the Arch User Repository (AUR)." - https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency Actually Arch Linux users and AUR maintainers noticed the attacks. I don't want to accuse anyone here of being responsible for the attacks, but exploiting the attacks, which have harmed a significant portion of the open-source community, namely us, for promotional purposes is also reprehensible. Am I misunderstanding this? English isn't my native language, did I perhaps translate it too literally?
