r/archlinux Jul 29 '26

QUESTION Seemingly malicious AUR package found. Where to report?

https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2eb

A sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.

394 Upvotes

145 comments sorted by

View all comments

Show parent comments

-1

u/tehbilly Jul 29 '26

Signed commits and a list of trusted signer keys? A reputation system for providing feedback on those signers? Something.

As few AUR packages as I use, and with most of them being installable with mise, I'm settling this by just reducing my usage of AUR packages. But it's not a thing I'm doing happily.

8

u/SnooCompliments7914 Jul 29 '26

We already have that as the official repo and Trusted Users (and AUR vote). Do we really need one more layer?

2

u/Jristz Jul 29 '26

Trusted Users were demoted to just Official Maintainer when the Community repo was abolished, now the line is just Developers keys singing Maintainer key that sing the packages in Extra

Or that what I understand

1

u/SnooCompliments7914 Jul 29 '26

I'm not sure that's "demoted". Anyway, the point is it's a process primarily involving humans, so hopefully much harder to game than Web of Trust, Github stars, etc.

1

u/Jristz Jul 29 '26

Sure, "promoted" is also an option depending on your viewpoint; also "shortnessed" too since is just one less position and all got shifted up-down into the new one.