Europe Pub
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
steam_lover@sh.itjust.worksB to Arch Linux@lemmy.ml · 1 day ago

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

external-link
message-square
6
link
fedilink
  • cross-posted to:
  • cybersecurity@infosec.pub
  • security@lemmy.ml
  • linux@lemmy.ml
  • technology@lemmy.world
  • linux@lemmy.world
  • hackernews@lemmy.bestiver.se
  • linux@sopuli.xyz
  • arch@programming.dev
57
external-link

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

steam_lover@sh.itjust.worksB to Arch Linux@lemmy.ml · 1 day ago
message-square
6
link
fedilink
  • cross-posted to:
  • cybersecurity@infosec.pub
  • security@lemmy.ml
  • linux@lemmy.ml
  • technology@lemmy.world
  • linux@lemmy.world
  • hackernews@lemmy.bestiver.se
  • linux@sopuli.xyz
  • arch@programming.dev
alert-triangle
You must log in or # to comment.
  • odseey@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    1 day ago

    More info here: https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577

    Everyone should check and make sure you don’t have one of these installed.

    • darcmage@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      9
      ·
      edit-2
      1 day ago

      updated version: https://gist.github.com/Kidev/85756c3dcad3623ca5604a8135bafd14

      https://github.com/lenucksi/aur-malware-check

      https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992

      As always, don’t execute random scripts before checking them.

      • bisby@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        1 day ago

        Oh fun. I had one of the packages installed, but not an infected version, and I hadn’t updated it during the window.

        Feels like a great reminder to keep a clean minimal system. Why I was keeping vidcutter installed and up to date when the last time I ran it was probably years ago.

        • darcmage@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          2
          ·
          1 day ago

          I thought for sure I had a few of them since some of the packages looked familiar but everything came out clean. Hopefully it stays that way.

          • bisby@lemmy.world
            link
            fedilink
            arrow-up
            2
            ·
            1 day ago

            My last update to vidcutter was from 2025 (based on my pacman logs). Some tools will scan for “did you install the bad package during the bad time period” and some will scan for “is the bad package name installed at all” - so i was able to identify that vidcutter was installed and I knew that the package names looking familiar made sense, and I was able to manually confirm that I was still clean. And now I have a lot of system pruning to do.

            But if you thing some packages look familiar, it might be worth double checking.

            • darcmage@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              2
              ·
              1 day ago

              Yeah I looked for them manually before coming across the scripts. I’ve been pretty careful with the aur and always check the comments on any new package I’m thinking of installing. Also I’ve gotten into the habit of checking the pkgbuilds after switching to paru from yay.

  • davetortoise@reddthat.com
    link
    fedilink
    arrow-up
    1
    arrow-down
    4
    ·
    1 day ago

    deleted by creator

Arch Linux@lemmy.ml

archlinux@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !archlinux@lemmy.ml

The beloved lightweight distro

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 84 users / day
  • 86 users / week
  • 193 users / month
  • 597 users / 6 months
  • 11 local subscribers
  • 9.77K subscribers
  • 143 Posts
  • 622 Comments
  • Modlog
  • mods:
  • k_o_t@lemmy.ml
  • BE: 0.19.18
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org