OpenMandriva disclosed an attempted sabotage of its distribution infrastructure after a contributor allegedly abused administrative privileges, deleting part of the project's GitHub repositories and pushing an empty package into the Cooker repository. The malicious package reportedly used the Obsoletes: field in an apparent attempt to remove or supersede large sets of GNOME and COSMIC packages, but the changes were detected before release and did not reach users.
The incident followed a broader governance and access crisis tied to the departure and loss of privileges of a key contributor who controlled important GitHub-based development and package-maintenance resources. OpenMandriva said the disruption affected repository access, package updates, and maintenance work, including some desktop-related packages and other delayed updates, and the project is now restoring deleted repositories, rebuilding workflows, and migrating package management infrastructure from GitHub to OneDev to reduce the risk of similar abuse.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
OpenMandriva said it is conducting a full system audit to identify any additional unauthorized changes following the alleged internal sabotage incident. The review accompanies ongoing restoration of deleted repositories and packages.
In response to the sabotage and access crisis, OpenMandriva began restoring deleted repositories, rebuilding maintenance processes, and migrating package management infrastructure from GitHub to OneDev to reduce the risk of similar abuse.
The attacker pushed an empty package or harmful package changes into the OpenMandriva Cooker repository, using package metadata such as the "Obsoletes:" field to target GNOME and COSMIC-related packages. OpenMandriva said the changes were detected before release and did not reach users.
OpenMandriva disclosed that a contributor allegedly abused administrative privileges after another contributor was removed from the Matrix chat for abusive behavior. The activity included deleting part of the project's GitHub repository and disrupting development infrastructure.
Following the incident and leadership departure, OpenMandriva said package updates and repository maintenance were disrupted, affecting Cooker and some desktop-related packages, with additional delays noted for work such as Mumble packaging.
OpenMandriva reported that former contributor Davide Beatrici lost maintainer status and package management privileges before the subsequent malicious activity against the project.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcebleepingcomputer.com
Open sourceforum.openmandriva.org
Open sourceopenmandriva.org
Open sourcephoronix.com
Open sourceopennet.me
Open sourceopennet.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.