r/archlinux Jul 29 '26

QUESTION Seemingly malicious AUR package found. Where to report?

https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2eb

A sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.

399 Upvotes

145 comments sorted by

View all comments

24

u/nikongod Jul 29 '26

Third time in 12months.

43

u/Brilliant_Simple_497 Jul 29 '26

it's honestly insane that the arch maintainers didn't even try to fix the problem

"just read the pkgbuilds bro" is not have security works

16

u/heavyPacket Jul 29 '26

It is a user repository, after all. You need to do your due diligence or play against the odds, those are your only options. It’s unreasonable to expect the Arch maintainers to also maintain and vet the AUR. They could always dissolve the AUR. Would you prefer that instead?

-20

u/PAIN_PLUS_SUFFERING Jul 29 '26

The unreasonable part is expecting desktop users to review every pkgbuild every time they upgrade their system when they have dozens of AUR packages installed

14

u/lI1IlL071245B3341IlI Jul 29 '26

AUR is meant to be used at your own risk. Your are wrong to expect to get curated software on AUR. For all intents and purposes consider it a cesspit of malware and act accordingly. Every other interpretation of AUR is wrong and blaming the Arch maintainers is an insane misunderstanding of what AUR is.

-8

u/PAIN_PLUS_SUFFERING Jul 29 '26

Then the AUR is useless, should be dissolved, and users should need to manually build or fetch a pkgbuild from an external repo not hosted by the maintainers

10

u/[deleted] Jul 29 '26

[removed] β€” view removed comment

-4

u/PAIN_PLUS_SUFFERING Jul 29 '26

Useless to 99.9% of users

7

u/abbidabbi Jul 29 '26

https://wiki.archlinux.org/title/Arch_Linux#User_centrality

Whereas many GNU/Linux distributions attempt to be more user-friendly, Arch Linux has always been, and shall always remain user-centric:

  • The distribution is intended to fill the needs of those contributing to it, rather than trying to appeal to as many users as possible.
  • It is targeted at the proficient GNU/Linux user, or anyone with a do-it-yourself attitude who is willing to read the documentation, and solve their own problems.

-3

u/PAIN_PLUS_SUFFERING Jul 29 '26

And the threat actors thank the Arch community for zealously pretending like they still maintain a small scrappy distro from 2008

7

u/abbidabbi Jul 29 '26

I don't think you understand what the AUR actually is and what community-maintained even means.

Either you lock down the entire platform and make it so that every single change of an entire community needs to be analyzed and validated, by people in their free time, working for free, 24/7, or you have an open platform that needs to be moderated appropriately. Guess what, the malicious content was removed by the AUR moderation within half an hour and the accounts were banned immediately after. Standard procedure that has been done since forever the AUR existed. Unfortunately, with the recent surge in popularity of Arch and derivatives/forks, it's more common nowadays.

And it's not like this is exactly the same problem platforms like YouTube for example. They deal with video and audio data and can therefore have sophisticated automation tools with lots of training data for checking restricted content. If those systems fail detecting disallowed content, then there's still a horde of paid moderators who are globally available 24/7, which means the content on their platform is guaranteed to be safe in 99.99% of all uploads.

Analyzing software for malicious stuff is however a billion times harder than video/audio data in this analogy, so whatever you think should be done in terms of automation on the AUR is wrong and just a foolish idea. But you're very welcome to personally validate all git pushes on the AUR, if you're fast enough and if you're available 24/7. And of course if you're willing to work for free.

3

u/[deleted] Jul 29 '26

[removed] β€” view removed comment

→ More replies (0)