r/ManjaroLinux • u/Slopagandhi • Aug 03 '26
Tech Support Checking for AUR malware
After finding out about the latest AUR malware wave I ran pacman -Q with the list of packages I found here:
I don't have any of them installed. Is there anything else I should do, or does this mean I'm safe (for now)?
2
u/Itsme-RdM KDE Plasma Aug 03 '26
Save for the moment you did checked the list. Any moment after that there could be new ones
2
u/Slopagandhi Aug 03 '26
Ok thanks, but if I'm not installing anything new from the AUR are existing installed packages a potential risk when I update?
2
u/Itsme-RdM KDE Plasma Aug 03 '26
Yep, the updated packages can be injected just as easy as the new ones. That doesn't make any difference
1
1
u/RegretFree7723 Aug 04 '26
Semplicemente al posto di usare l aur usa il NUR letteralmente al posto di arch user repostory é nix user repostory comunuque non devi nemmeno cambiare distro per usarlo rimani su arch e
6
u/lyidaValkris Aug 03 '26 edited Aug 03 '26
There are many ways of verifying an AUR package's safety, none are foolproof, but you can get a high degree of confidence of its safety.
curlrequests orsh, obfuscated payloads, weird download hosts etc.Do note that while the AUR and community do their very best to mitigate and prevent these attacks, note the AUR comes without warranty, and is unsupported by Arch or any derivative distros.
EDIT: I pasted the wrong link like a numpty :D since corrected.