- Joined
- Dec 19, 2022
Every package manager I know of verifies the signature before it'll install any packages, so no, you can't just inject malware into an .rpm to take out IBM or whatever. The packages will fail to verify and the file will be downloaded from fallback servers until they get one whose signature matches the expected hash.Some malware injected into packages or a script is just a disgruntled tranny janny with the right access/server-who hosts-the-stuff exploit away.
What you can do is take over a project on github and inject your malware directly into the source code. If a package is compiled with the compromised code there's nothing you can do short of announcing the issue and encouraging every maintainer to lock to a non-compromised version until the project can be forked out of your control and cleaned up. This is what happened to node-ipc.