The AUR (Arch Linux User Repository) is continuing to be flooded with malicious code.
As of this writing, the Arch team has found at least 1,579 malicious packages (roughly 1.4% of all packages within the AUR), with more packages being updated with malicious code this morning.
This includes several popular utilities and libraries, including: gtkimageview, gdl, libgdata, and python-future.
A partial list of impacted packages can be found here:
md.archlinux.org/s/SxbqukK6I…
There now appears to be close to 900 packages, in the Arch Linux User Repository (AUR) which contain malicious code (including keyloggers).
Which means we are closing in on 1% of the entire AUR containing deliberately malicious code.