Sygnia says Velvet Ant modified Linux PAM and OpenSSH components to steal credentials and maintain stealthy access since 2016 ...
Looks like the Arch Linux AUR (Arch User Repository) needs some better security and package checks - as some malicious users ...