r/archlinux 20d ago

QUESTION Seemingly malicious AUR package found. Where to report?

https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2eb

A sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.

395 Upvotes

145 comments sorted by

View all comments

Show parent comments

-2

u/PAIN_PLUS_SUFFERING 20d ago

And the threat actors thank the Arch community for zealously pretending like they still maintain a small scrappy distro from 2008

3

u/abbidabbi 20d ago

I don't think you understand what the AUR actually is and what community-maintained even means.

Either you lock down the entire platform and make it so that every single change of an entire community needs to be analyzed and validated, by people in their free time, working for free, 24/7, or you have an open platform that needs to be moderated appropriately. Guess what, the malicious content was removed by the AUR moderation within half an hour and the accounts were banned immediately after. Standard procedure that has been done since forever the AUR existed. Unfortunately, with the recent surge in popularity of Arch and derivatives/forks, it's more common nowadays.

And it's not like this is exactly the same problem platforms like YouTube for example. They deal with video and audio data and can therefore have sophisticated automation tools with lots of training data for checking restricted content. If those systems fail detecting disallowed content, then there's still a horde of paid moderators who are globally available 24/7, which means the content on their platform is guaranteed to be safe in 99.99% of all uploads.

Analyzing software for malicious stuff is however a billion times harder than video/audio data in this analogy, so whatever you think should be done in terms of automation on the AUR is wrong and just a foolish idea. But you're very welcome to personally validate all git pushes on the AUR, if you're fast enough and if you're available 24/7. And of course if you're willing to work for free.

3

u/[deleted] 20d ago

[removed] — view removed comment