"Malware Spread Through Ubuntu's 'command-not-found' Tool"
Originally Published 1 year ago — by BleepingComputer

A logic flaw in Ubuntu's 'command-not-found' package suggestion system and the snap package repository could allow attackers to promote malicious Linux packages to users, posing a significant supply chain risk for Linux and Windows Subsystem for Linux (WSL) users. The flaw enables attackers to impersonate legitimate APT packages with malicious snap packages, exploiting loopholes in the naming and aliasing system of snaps. Steps to mitigate the risks include users verifying package authenticity and Snap developers registering similar names for their apps.
