this post was submitted on 16 Mar 2026
437 points (91.5% liked)
Linux
12841 readers
1321 users here now
A community for everything relating to the GNU/Linux operating system (except the memes!)
Also, check out:
Original icon base courtesy of lewing@isc.tamu.edu and The GIMP
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Not this kind of malware specifically. Their snap repo has a policy of allowing fully automatic app submission as long as the app is sandboxed. This led to multiple people submiting modified crypto wallet apps under the branding of the original trusted devs, without any challenge on Ubuntu's part. You could also put up a Librewolf version that leaks all the passwords you type in, or a Signal without encryption - ✨ endless creativity ✨. This specific attack is harder on Flathub as all apps have to be checked by the moderation team, and they should ask question if your Librewolf package is built from your own repo.