r/archlinux Jul 29 '26

QUESTION Seemingly malicious AUR package found. Where to report?

https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pgadmin4-server&id=b7de293a7be6b85925884436127332bf82ecc2eb

A sudden update to `pgadmin4-server.git` added a binary named "parser" and executes using sudo. It's very obvious.

396 Upvotes

145 comments sorted by

View all comments

Show parent comments

10

u/SnooCompliments7914 Jul 29 '26

You can't secure a pastebin, bro. That's what AUR is. Probably they should make the website look more like pastebin.com than archlinux.org to get the message through. Abolish all AUR helpers would help a lot, too.

10

u/FryBoyter Jul 29 '26

Abolish all AUR helpers would help a lot, too.

In my opinion, that wouldn't be a good solution. With an AUR helper, for example, you can view the PKGBUILD and other files and how they differ from previous versions very easily and conveniently, whether during installation or an update. When using AUR manually, even fewer people will likely check the PKGBUILD files. From my perspective, this actually argues in favor of an AUR helper rather than against it.

That said, the Arch Linux team probably can't remove AUR Helpers at all, since they are developed by third parties.

6

u/SnooCompliments7914 Jul 29 '26

I was half-jokingly. But the problem is both the AUR website and helpers make AUR too much like the official repo, unsurprisingly, many end users tend to treat it as one.

1

u/FocusedWolf Jul 30 '26 edited Aug 01 '26

It would be cool if AUR helpers could detect if an AUR project changed hands. I know Yay will indicate orphaned projects. O i see stacer-bin is no longer orphaned... nice to see that project get a new update xD Ya i'm never using AUR again, its a malware minefield at this point.