OpenMandriva Linux Project Hit by Attempted Internal Sabotage
A long-running dispute among contributors to the OpenMandriva Linux project has escalated into an attempted act of internal sabotage. The perpetrator, Davide Beatrici, a leading developer of the instant messaging app Mumble and a friend of the attacker, deliberately deleted crucial repositories and pushed an empty package that could have damaged users’ systems.
The OpenMandriva team is an independent, community-run Linux distribution that was forked from Mandriva Linux in 2012. The distro stands out for using the LLVM/Clang toolchain instead of GCC to build most of its components. This approach has been a deliberate design choice, distinguishing OpenMandriva from other Linux distributions.
According to AngryPenguin, a long-time OpenMandriva developer and maintainer, Beatrici’s actions were motivated by his disagreement with the project’s focus on KDE and LXQt environments. A group of contributors had voiced their opposition to this direction, leading to tensions within the community. In an attempt to settle the dispute, AngryPenguin states that some members deleted a crucial configuration file without informing anyone else.
Beatrici, who held administrative privileges due to his previous contributions, took advantage of his access to delete repositories and push the empty package. This malicious action had the potential to cause significant harm to users, as it could have led to broken dependencies and unstable system performance. Fortunately, the OpenMandriva team is currently restoring the deleted repositories and conducting a thorough audit to identify any other unauthorized changes.
When questioned by BleepingComputer about his involvement, Beatrici denied any intention to sabotage the project or harm its users. He claimed that his goal was to “correct” what he perceived as errors in the project’s configuration files and package management. However, AngryPenguin emphasized that these actions still constituted a serious breach of trust within the community.
In a surprising move, the OpenMandriva team has chosen not to pursue legal action against Beatrici, despite acknowledging his actions as a criminal offense. Instead, they are focusing on rebuilding their systems and continuing their development work uninterrupted.
The incident serves as a stark reminder of the importance of internal security measures within open-source projects. As AngryPenguin pointed out, “Test every layer before attackers do.” This statement is particularly relevant in the context of this attempted sabotage, highlighting the need for robust access controls, regular audits, and vigilant community monitoring to prevent similar incidents from occurring.
For users and contributors alike, this incident underscores the importance of maintaining a secure and transparent development environment. By acknowledging the risks associated with internal conflicts and taking proactive measures to mitigate them, open-source projects can minimize the impact of such events and ensure continued stability and growth.
Source: Bleeping Computer — 2026-07-09