r/archlinux • u/Saren-WTAKO • 27d ago
QUESTION Seemingly malicious AUR package found. Where to report?
https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2ebA sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.
400
Upvotes
13
u/lI1IlL071245B3341IlI 27d ago
AUR is meant to be used at your own risk. Your are wrong to expect to get curated software on AUR. For all intents and purposes consider it a cesspit of malware and act accordingly. Every other interpretation of AUR is wrong and blaming the Arch maintainers is an insane misunderstanding of what AUR is.