New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Bunch of AUR packages compromised
in General
Hi, your friendly neighborhood pechgoblin is back again with some juicy news for Arch Linux users.
https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
Have fun ![]()
Thanked by 1layer7

Comments
npm involved in this mess, of course.
Arch Users can use this script to check if they're affected.
https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992
yay.Well not really. There's a good reason normal people don't use AUR.
It's always NPM
Chaotic AUR should abandon affected packages.
If anyone has anything from AUR installed, it may be a good idea to not perform updates right now. Seems like entire AUR currently is getting attacked with malicious packages:
There are more and more packages getting infected in recent hours, now using different malicious
js-digestpackage and bun package manager. List of malicious packages is now estimated at almost 900.Gaining maintainer access to AUR packages appears to be done via the mechanism of orphaned packages:
https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577/4
https://old.reddit.com/r/archlinux/comments/1u3tn4e/tons_of_new_infected_aur_packages_were_just/
I was about to update my Manjaro, big oof.
That nobody notices that, is beyond me.
Wtf are you really using it?
Good thing I've been lobotomized
Wow, their security etiquette is really amazing, about as safe as a free entry, no questions asked, orgy.
No wonder they got ill.
Its installed yes, actually I wanted to install Debian again but I got to lazy.
It works, its bleeding clusterfucking edge, so everything can break at any moment but it works.
Hi,
if this is true, then someone with endless faith in humans was the architect of this security decisions
Quiet adventurous 
That this was not already exploited long long ago?! Quiet surprising.
Anyway, good catch security news wise!
Good thing I haven't updated my steam deck yet... Valve did not sync the repo...?
Do they even use AUR?
they use their own arch repo iirc
People need to stop installing random crap from the AUR.
Yeah, if i'm installing something from a third party repository the last thing i would want is there being a possibility of a random maintainer change. I've chosen to trust this repo and this maintainer (or whoever that person feels to make a good successor) and certainly not some random guy who managed to hand in a largely automated request.
Seriously.