OpenMandriva says a contributor tried to damage the Linux distribution project by deleting repositories and publishing a package change that could have harmed users' systems. The project says repositories on GitHub were wiped in part and an empty package was pushed to the Cooker development branch to obsolete GNOME and COSMIC desktop packages. OpenMandriva is restoring affected data and auditing systems for any other unauthorized changes.
Why it matters: This matters because a trusted contributor account allegedly made destructive changes inside a software project, showing how insider or maintainer abuse can become a supply-chain risk for downstream users. OpenMandriva users and mirrors should watch for project guidance, avoid unreviewed development-branch updates, and verify package integrity while the audit continues.
Bill Toulas
2026.07.09
100% relevant
This article appears to be the first clear report of the OpenMandriva repository deletion and harmful package publication incident, establishing a distinct new software supply-chain sabotage story.
← Back to all stories