As a Package Maintainer for @archlinux, I was involved in the removal of the malware that was distributed through the Arch User Repository (AUR) last month. Here's my blog post on this topic, detailing what happened, some things I learned, and how the malware worked:
https://www.mh4ckt3mh4ckt1c4s.xyz/blog/aur-chaos-malware-analysis/






