Looks like the Arch Linux AUR (Arch User Repository) needs some better security and package checks - as some malicious users ...
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud ...