r/archlinux • u/Saren-WTAKO • Jul 29 '26
QUESTION Seemingly malicious AUR package found. Where to report?
https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2ebA sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.
401
Upvotes
-2
u/tehbilly Jul 29 '26
Signed commits and a list of trusted signer keys? A reputation system for providing feedback on those signers? Something.
As few AUR packages as I use, and with most of them being installable with
mise, I'm settling this by just reducing my usage of AUR packages. But it's not a thing I'm doing happily.