OpenMandriva Linux Says Angry Contributor Wiped Years of Work

A developer with admin keys deleted repositories and pushed a package that could have broken user systems, after a dispute over the project's direction.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration for the story: OpenMandriva Linux Says Angry Contributor Wiped Years of Work
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • OpenMandriva, a community-run Linux operating system, said a contributor deleted repositories and pushed a harmful package in November 2025.
  • The developer named by the project is Davide Beatrici, best known as the lead developer of the Mumble voice chat app.
  • Beatrici held administrator rights because he had previously helped mirror the project's code to his own private OneDev instance.
  • He denies the word "sabotage" but confirms he deleted the GNOME and Cosmic desktop repositories and pushed a package that would remove them from users' systems.
  • OpenMandriva says it is restoring the data and will not press criminal charges.

OpenMandriva, a small Linux distribution run by volunteers, says one of its own contributors tried to burn the project down from the inside.

The project is a free operating system kept alive by a handful of maintainers since it forked from Mandriva Linux in 2012. Not a household name, but thousands of people run it, and the code lives in shared online repositories that any trusted developer can edit.

That trust is the story here.

According to a forum post by long-time maintainer AngryPenguin, first reported by BleepingComputer, the trouble started with an internal dispute. A contributor's abusive behaviour toward certain users caused some members to leave. Then Davide Beatrici, a friend of the person at the centre of the row, decided to act.

Beatrici had administrator privileges on the project's code, meaning he could delete or overwrite files at will. He'd earned those keys by helping the team mirror their repositories to a private OneDev server he ran. Nobody had taken them back when the friendship soured.

What did the contributor actually do?

He deleted the GitHub repositories for GNOME and Cosmic, the graphical desktop environments users see when they log in. The code represented nearly a decade of work.

Then he did something worse. He pushed an empty package to Cooker, OpenMandriva's development branch, and marked it as replacing GNOME and Cosmic. In plain English: any user who ran a routine software update would've had those desktops quietly uninstalled. A normal update, the kind people click through without thinking, becomes the delivery mechanism for the damage.

Beatrici rejects the word "sabotage". In a statement to The Lunduke Journal he said his goal was never to harm the distribution or its users, and that he acted because other members had deleted a configuration file from his server without asking first. He also said the project was focusing on KDE and LXQt instead of the desktops he cared about.

Whichever way you frame the motive, the effect was identical. A person with admin rights used them to break things other people depended on.

Should regular users be worried?

Probably not, if you act normally. OpenMandriva says it's restoring the deleted repositories and running a full audit for any other unauthorised changes. If you run OpenMandriva, hold off on major updates until the team confirms the Cooker branch is clean and stick to the stable release for now.

The team also said that although Beatrici's actions amount to a criminal offence in their view, they won't pursue legal action.

We first covered OpenMandriva on 9 July 2026, a stretch of Linux reporting that now runs to 21 stories on the site. This one sits in the same uncomfortable space: a security failure that didn't need a remote exploit, just a stale permissions list.

What the post-mortem will say, plainly: this was an access management failure long before it was a sabotage story. Admin rights were handed out for a specific migration job and never reviewed. When the relationship broke, the keys were still in the drawer.

Audit who has write access to your repositories this week, not next quarter.

© 2026 Threat Vectr