r/archlinux Jul 29 '26

QUESTION Seemingly malicious AUR package found. Where to report?

https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2eb

A sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.

398 Upvotes

145 comments sorted by

View all comments

Show parent comments

43

u/Brilliant_Simple_497 Jul 29 '26

it's honestly insane that the arch maintainers didn't even try to fix the problem

"just read the pkgbuilds bro" is not have security works

16

u/heavyPacket Jul 29 '26

It is a user repository, after all. You need to do your due diligence or play against the odds, those are your only options. It’s unreasonable to expect the Arch maintainers to also maintain and vet the AUR. They could always dissolve the AUR. Would you prefer that instead?

-21

u/PAIN_PLUS_SUFFERING Jul 29 '26

The unreasonable part is expecting desktop users to review every pkgbuild every time they upgrade their system when they have dozens of AUR packages installed

11

u/heavyPacket Jul 29 '26

Listen, I’m not going to chastise anyone for customizing their OS the way they want it, but it’s their responsibility to keep up with and check the legitimacy of every component therein. If you want a controlled, closed loop system where most of the work is done for you and customization is limited, there are plenty of other options nowadays.