Lemmy.World
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
steam_lover@sh.itjust.worksB to Arch Linux@lemmy.ml · 18 hours ago

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

external-link
message-square
7
link
fedilink
  • cross-posted to:
  • technology
  • linux
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
55
external-link

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

steam_lover@sh.itjust.worksB to Arch Linux@lemmy.ml · 18 hours ago
message-square
7
link
fedilink
  • cross-posted to:
  • technology
  • linux
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
alert-triangle
You must log in or # to comment.
  • odseey
    link
    fedilink
    English
    arrow-up
    11
    ·
    16 hours ago

    More info here: https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577

    Everyone should check and make sure you don’t have one of these installed.

    • darcmage@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      9
      ·
      edit-2
      10 hours ago

      updated version: https://gist.github.com/Kidev/85756c3dcad3623ca5604a8135bafd14

      https://github.com/lenucksi/aur-malware-check

      https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992

      As always, don’t execute random scripts before checking them.

      • bisby
        link
        fedilink
        arrow-up
        5
        ·
        14 hours ago

        Oh fun. I had one of the packages installed, but not an infected version, and I hadn’t updated it during the window.

        Feels like a great reminder to keep a clean minimal system. Why I was keeping vidcutter installed and up to date when the last time I ran it was probably years ago.

        • darcmage@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          2
          ·
          14 hours ago

          I thought for sure I had a few of them since some of the packages looked familiar but everything came out clean. Hopefully it stays that way.

          • bisby
            link
            fedilink
            arrow-up
            2
            ·
            14 hours ago

            My last update to vidcutter was from 2025 (based on my pacman logs). Some tools will scan for “did you install the bad package during the bad time period” and some will scan for “is the bad package name installed at all” - so i was able to identify that vidcutter was installed and I knew that the package names looking familiar made sense, and I was able to manually confirm that I was still clean. And now I have a lot of system pruning to do.

            But if you thing some packages look familiar, it might be worth double checking.

            • darcmage@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              2
              ·
              14 hours ago

              Yeah I looked for them manually before coming across the scripts. I’ve been pretty careful with the aur and always check the comments on any new package I’m thinking of installing. Also I’ve gotten into the habit of checking the pkgbuilds after switching to paru from yay.

  • davetortoise@reddthat.com
    link
    fedilink
    arrow-up
    1
    arrow-down
    3
    ·
    9 hours ago

    “No way to prevent this” says only distribution where this regularly happens

Arch Linux@lemmy.ml

archlinux@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

The beloved lightweight distro

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 79 users / day
  • 86 users / week
  • 196 users / month
  • 603 users / 6 months
  • 2.35K local subscribers
  • 9.77K subscribers
  • 417 Posts
  • 2.66K Comments
  • Modlog
  • mods:
  • k_o_t@lemmy.ml
  • UI: 0.19.18-4-g685b50ce
  • BE: 0.19.18-8-g5d8cbdd9d
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org