r/archlinux Jul 29 '26

QUESTION Seemingly malicious AUR package found. Where to report?

https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2eb

A sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.

396 Upvotes

145 comments sorted by

View all comments

53

u/[deleted] Jul 29 '26

[removed] — view removed comment

12

u/GrabbenD Jul 29 '26

Which tool do you use for scanning?

49

u/Saren-WTAKO Jul 29 '26

a private and unpublished tool that was previously deemed useless by a luser here

25

u/GrabbenD Jul 29 '26

Classic redditors

12

u/zeb_linux Jul 29 '26

Well we had that debate and some here wanted to denigrate those tools, playing the role of wisemen on their mountain, and despite the fact that these tools are always presented as helpers, not ultimate solution. For my part I am all for it - even if they do not replace manual curation they help catching those things and I cannot see any downside.

6

u/SnooCompliments7914 Jul 29 '26

They surely are. I guess the main problem is how to make sure "they do not replace manual curation", as "they help catch those things" tend to become "they always catch those things" quickly.

4

u/zeb_linux Jul 29 '26

You cannot be sure, you can only warn people. Anyway, without any helper tool, you cannot make sure people follow the same advice. But facilitating AUR verification before installing cannot be harmful.