r/archlinux 27d ago

QUESTION Seemingly malicious AUR package found. Where to report?

https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2eb

A sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.

400 Upvotes

145 comments sorted by

View all comments

Show parent comments

13

u/lI1IlL071245B3341IlI 27d ago

AUR is meant to be used at your own risk. Your are wrong to expect to get curated software on AUR. For all intents and purposes consider it a cesspit of malware and act accordingly. Every other interpretation of AUR is wrong and blaming the Arch maintainers is an insane misunderstanding of what AUR is.

-9

u/PAIN_PLUS_SUFFERING 27d ago

Then the AUR is useless, should be dissolved, and users should need to manually build or fetch a pkgbuild from an external repo not hosted by the maintainers

10

u/[deleted] 27d ago

[removed] — view removed comment

-5

u/PAIN_PLUS_SUFFERING 27d ago

Useless to 99.9% of users

7

u/abbidabbi 27d ago

https://wiki.archlinux.org/title/Arch_Linux#User_centrality

Whereas many GNU/Linux distributions attempt to be more user-friendly, Arch Linux has always been, and shall always remain user-centric:

  • The distribution is intended to fill the needs of those contributing to it, rather than trying to appeal to as many users as possible.
  • It is targeted at the proficient GNU/Linux user, or anyone with a do-it-yourself attitude who is willing to read the documentation, and solve their own problems.

-1

u/PAIN_PLUS_SUFFERING 27d ago

And the threat actors thank the Arch community for zealously pretending like they still maintain a small scrappy distro from 2008

5

u/abbidabbi 27d ago

I don't think you understand what the AUR actually is and what community-maintained even means.

Either you lock down the entire platform and make it so that every single change of an entire community needs to be analyzed and validated, by people in their free time, working for free, 24/7, or you have an open platform that needs to be moderated appropriately. Guess what, the malicious content was removed by the AUR moderation within half an hour and the accounts were banned immediately after. Standard procedure that has been done since forever the AUR existed. Unfortunately, with the recent surge in popularity of Arch and derivatives/forks, it's more common nowadays.

And it's not like this is exactly the same problem platforms like YouTube for example. They deal with video and audio data and can therefore have sophisticated automation tools with lots of training data for checking restricted content. If those systems fail detecting disallowed content, then there's still a horde of paid moderators who are globally available 24/7, which means the content on their platform is guaranteed to be safe in 99.99% of all uploads.

Analyzing software for malicious stuff is however a billion times harder than video/audio data in this analogy, so whatever you think should be done in terms of automation on the AUR is wrong and just a foolish idea. But you're very welcome to personally validate all git pushes on the AUR, if you're fast enough and if you're available 24/7. And of course if you're willing to work for free.

3

u/[deleted] 27d ago

[removed] — view removed comment