Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
steam_lover@sh.itjust.worksB to Arch Linux@lemmy.ml ·
edit-2
18 hours ago

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

external-link
message-square
7
fedilink
  • cross-posted to:
  • linux@lemmy.ml
  • technology@hexbear.net
  • hackernews@lemmy.bestiver.se
  • linux@sopuli.xyz
  • arch@programming.dev
44
external-link

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

steam_lover@sh.itjust.worksB to Arch Linux@lemmy.ml ·
edit-2
18 hours ago
message-square
7
fedilink
  • cross-posted to:
  • linux@lemmy.ml
  • technology@hexbear.net
  • hackernews@lemmy.bestiver.se
  • linux@sopuli.xyz
  • arch@programming.dev
alert-triangle
You must log in or # to comment.
  • davetortoise@reddthat.com
    link
    fedilink
    arrow-up
    1
    ·
    8 hours ago

    “No way to prevent this” says only distribution where this regularly happens

  • odseey@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    16 hours ago

    More info here: https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577

    Everyone should check and make sure you don’t have one of these installed.

    • darcmage@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      8
      ·
      edit-2
      10 hours ago

      updated version: https://gist.github.com/Kidev/85756c3dcad3623ca5604a8135bafd14

      https://github.com/lenucksi/aur-malware-check

      https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992

      As always, don’t execute random scripts before checking them.

      • bisby@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        edit-2
        14 hours ago

        Oh fun. I had one of the packages installed, but not an infected version, and I hadn’t updated it during the window.

        Feels like a great reminder to keep a clean minimal system. Why I was keeping vidcutter installed and up to date when the last time I ran it was probably years ago.

        • darcmage@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          2
          ·
          14 hours ago

          I thought for sure I had a few of them since some of the packages looked familiar but everything came out clean. Hopefully it stays that way.

          • bisby@lemmy.world
            link
            fedilink
            arrow-up
            2
            ·
            14 hours ago

            My last update to vidcutter was from 2025 (based on my pacman logs). Some tools will scan for “did you install the bad package during the bad time period” and some will scan for “is the bad package name installed at all” - so i was able to identify that vidcutter was installed and I knew that the package names looking familiar made sense, and I was able to manually confirm that I was still clean. And now I have a lot of system pruning to do.

            But if you thing some packages look familiar, it might be worth double checking.

            • darcmage@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              2
              ·
              13 hours ago

              Yeah I looked for them manually before coming across the scripts. I’ve been pretty careful with the aur and always check the comments on any new package I’m thinking of installing. Also I’ve gotten into the habit of checking the pkgbuilds after switching to paru from yay.

Arch Linux@lemmy.ml

archlinux@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !archlinux@lemmy.ml

The beloved lightweight distro

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 62 users / day
  • 79 users / week
  • 159 users / month
  • 546 users / 6 months
  • 93 local subscribers
  • 9.77K subscribers
  • 423 Posts
  • 2.77K Comments
  • Modlog
  • mods:
  • k_o_t@lemmy.ml
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org