Hi Folks, Related to yesterday/today thread: Malicious package upstream: plasma6-applet-quicklaunch (6.5.80-3)
It seems GitHub as been fucked, please check your package upstream repos. https://thehackernews.com/2026/10/credential-stealing-github-actions.html Just spreading the word. Emiliano Gandini Outeda emiliano-go[dot]com emiliano.gandini[at]protonmail[dot]com
publickey - [email protected] - 0xF759D6D4.asc
Description: application/pgp-keys
signature.asc
Description: OpenPGP digital signature
