After testing Void in a vm earlier, I can say this is my personal second choice of distro
voidlinux.org
REALLY WISH PEOPLE REALISED THIS.
ARCH AND ARCH BASED DISTROS ARE BEAUTIFUL
MEANWHILE THE AUR IS SUCH A FUCKFEST THATS EQUIVALENT OF GETTING MUGGED WHILE WALKING IN THE WORST TOWNS OF UK AT NIGHT.
I agree, shut down aur, HARDEN TF OUTTA IT. Build in kill switches in aur helper packages as well.
Cause people are blaming Linux, which is just a kernel btw and moving back to Winslop which already does what the malicious packages on aur is doing rn but with a fancy corpo tag on it.
I personally am surprised the AUR has lasted this long. I personally believe that negatives outweigh the positives with having ANYONE be able to submit packages to the AUR. I say better moderation / verification or everyone focuses on official packages instead.
Again, it is important to note that this attack does NOT affect regular Arch Linux packages, only those packages installed via the Arch User Repository (AUR).