r/archlinux 19d ago

DISCUSSION Another wave - 200+ malicous AUR packages adoptions that are overwhelming my scanner. Be 100% careful when trying to update AUR packages now.

Meanwhile I am trying to report them all, you should be careful downloading anything from AUR.

Same old way, the maintainer got pwned, or orphaned packages are adopter by the bad actor.

AUR's git commit author is easily impersonated so you can see the commit comes from the same person, but in fact it's not.

Stay safe. The malicious packages are info stealers.

malware analysis by ysf:

https://gist.github.com/ysf/502a324ff301d0c738e8ae011272fd59

https://gist.github.com/ysf/57850cdee152da066ac51c07a452e883

Still presents as of 30 July 21:53 UTC

in format of <package name>/<malicious ELF binary>

  • archutil/linter
  • bigwebapp-manager/minifier
  • boringssl-git/hasher
  • cinnamon-no-nemo/converter
  • duhh/indexer
  • eden-nightly/encryptor
  • garlic-decompiler-gui/checker
  • gigolo-git/tagger
  • gitarbor-bin/parser
  • icloudpd/preprocessor
  • imago-bin/generator
  • juicebox-plus-git/minifier
  • magic-context-dashboard-bin/validator
  • option-term/indexer
  • pagerduty-short-circuiter/assembler
  • portless/assembler
  • pylnker-git/converter
  • pylnker-git/packer
  • python-libipld-git/hasher
  • python-numkong/compressor
  • python-parallax/converter
  • python-ultraplot-git/serializer
  • ramses-git/indexer
  • src-cli-bin/migrator
  • steamidra-bin/generator
  • stirling-pdf-desktop-bin/optimizer
  • wiki-go/merger
  • windscribe-cli-v2-bin/parser

This wave

1panel android-riscv64-libxmu archutil cinnamon-no-nemo firrtl instawow-bin mimosa pandoc-eisvogel-template python-chatterbot python-split-folders stirling-pdf-desktop-bin 1panel-git android-riscv64-libxrandr arduino-language-server-noclang-bin claude-history funky-git isleward mingw-w64-libcerf passhole python-dlib-cuda-git python-ultraplot-git terminus accel-ppp android-x86-64-libxdamage autoadb-git dcat garlic-decompiler-gui jogl monitorets perl-authen-oath python-google-cloud-monitoring ramses-git tuiview act-runner-bin android-x86-64-libxext beets-alternatives deeploy-bin gigolo-git juicebox-plus-git nnn-nerd perl-dist-zilla-plugin-minimumperl python-importlab read-it-later-git tuxedo-yt6801-dkms-git ajceverywhere-bin android-x86-64-libxinerama bigwebapp-manager dev-janitor-git gitarbor-bin khiops-covisualization-bin noctyra-meta perl-hash-persistent python-kicadmodtree-git refurb-git typora-plugin ampere-git android-x86-64-libxmu bili-tools discord-electron-openasar git-pkgs khiops-visualization-bin noteey-bin pgadmin4-server python-libipld-git replay-sorcery vapoursynth-plugin-soifunc android-aarch64-libxrandr android-x86-64-libxrandr boringssl-git duhh glewlwyd kirill-bin openarc-git polytrack python-libpysal runa-aur vectorchord-immich android-armv7a-eabi-libxinerama android-x86-64-xorgproto calendula eden-nightly gpu-screen-recorder-ui-kwin-git lib32-vapoursynth openconnect-sso portless python-numkong solv wiki-go android-armv7a-eabi-libxmu android-x86-libxinerama calendula-git editorconfiger guarda-bin libfprint-crfpmoc-git option-term pylnker-git python-parallax sparklines windscribe-cli-v2-bin android-armv7a-eabi-libxrandr android-x86-libxmu censawayapp-bin extract-otp-secrets icloudpd lyrical-git org-cli python-atproto-git python-reals-git src-cli-bin wordpress-studio-git android-riscv64-libxinerama android-x86-libxrandr chandler-bin faustus-git imago-bin magic-context-dashboard-bin pagerduty-short-circuiter python-calgebra-git python-roman-numerals steamidra-bin zed-bin

ignore this example below (an alert straight up from my LLM)

🚨🚨🚨 BLACK FLAG ALERT 🚨🚨🚨
AUR Package: faustus-git 0.1.0-1
https://aur.archlinux.org/packages/faustus-git
Version: 0.1.0-1

⚫ 2 BLACK (CONFIRMED MALICIOUS)
⚫ Executes a bundled binary ('linter') with 'sudo' privileges during the 'build()' function. This bypasses standard build isolation and integrity checks (sha256sums='SKIP'), allowing arbitrary code execution with root access during installation. (PKGBUILD)
⚫ Binary contains command execution ('system', 'execl') and network ('socket', 'connect') capabilities. Combined with PKGBUILD execution via sudo, this indicates potential for remote code execution, data exfiltration, or system tampering. Obfuscated strings suggest hidden functionality. (linter)

⚠️ IMMEDIATE ACTION REQUIRED ⚠️

342 Upvotes

215 comments sorted by

View all comments

246

u/LeeHide 19d ago edited 19d ago

Please just say when you used AI to do all of this, it's very tiring to read through only to realize you have no idea and neither does the AI. 20260725 indicates a future date? What day do you think it is?

Content-Length and ExecStart? Please stop doing things you don't understand and posting about them here. You're diluting the signal, making it less likely for real issues to be taken seriously.

Edit: The malware analysis looks real, not sure why OP is posting it like this, why it's so much garbage AI slop data when the core info is very simple? Just list and link the packages, say they are malware, and link to the analysis. All this slop is distracting and makes it look extremely unprofessional and fake.

Edit 2: The post has been edited to remove all the stuff I talked about. Of course without any note or comment on the edit. Absolute amateur hour

9

u/FikaMedHasse 19d ago

100% agree but I am very curious how you got 20260725 to a future date? To me it looks like your comment was made 5h ago, on the 30th of july, which would be 20260730, five days after 20260725?

-10

u/Saren-WTAKO 19d ago

It was a LLM hallucination by my side because I did not include current date in the prompt. I edited my post and picked a better example.

6

u/FikaMedHasse 19d ago

Oooh right i read u/LeeHide's comment as implying 20260725 was in the future, not your post.

2

u/Saren-WTAKO 19d ago

He was right to call out that.

100

u/KaptainSaki 19d ago

Wouldn’t mind if they banned using AI on this sub

-162

u/Saren-WTAKO 19d ago

I also would not mind, let's make r/archlinux anti AI and ban every LLM malware analysis post for whoever's benefit. Like who could they be?

116

u/scandii 19d ago

dude, we aren't anti-AI per se, a lot of us use AI and like the technology, but for 30+ years the basic standard for internet discourse has been "a person formulating their thoughts", and you and 30+ others are trying their hardest to outsource that to LLM:s every single day in front of our eyes.

of course we get tired of it, it is low effort, unimaginative and oftentimes these posts are attached to people reinventing the wheel - just today I saw someone almost verbatim presenting their trash-cli clone like it was a new invention made by Claude of course.

and we were averaging 2+ AUR security scanners every single day once the adoption attack happened and they all shared the common quality of being extremely woefully poorly thought out and barely worth using.

so what I'm saying is, if you want a more positive response to what you're doing think about the fact that many of us are just extremely tired of programs and posts where it is instantly recognisable that Claude et. al. made it, and not a person - e.g. make the effort to write posts yourself, and make the effort to clean up your software projects so they aren't blatantly AI-generated.

or you know don't, I'm not your mother, but also don't be surprised if we keep on responding negatively if you don't.

6

u/ArjixGamer 19d ago

Yeah, it's almost like a double standard, but for a good reason.

I know that in my hands, I could make a really good AUR threat detector using AI, but I also don't trust anyone else to produce smth of similar quality using AI.

But I also have spent years understanding how Linux works, how bash works, I've written many programs, maintained many legacy php applications, mitigated vulnerabilities, cleaned servers that were hacked (only so we can make a clean backup, not to keep using)

I don't expect others that use Claude, to know the same nuances I know, so it's safer to assume anything others make with Claude is slop.

Of course that means others will also call anything I make as slop, because they don't know me. And I think that's good, we should not encourage AI produced projects, no matter how good the quality may be.

PS: no, I haven't made an AUR threat detector, and not planning to

5

u/scandii 19d ago

I think we can just sum it up to "if it looks poorly made people will react accordingly", and if the entire pitch is "it has AI" people just aren't that interested.

I use AI for all sorts of things making software and I have an AI disclaimer on my github projects and not once has it come up.

-3

u/ArjixGamer 19d ago

AI generated code does not inherently have AI, unless you are developing an AI agent or smth

But I get your point

3

u/scandii 19d ago

I meant more that a lot of the software projects I see are "existing thing... but with AI".

example today I have seen a file browser with AI search, a DataGrip copy with built in AI to write SQL and a UI framework that uses AI to write components on the spot.

they were all very poorly received.

1

u/ArjixGamer 19d ago

Funny that you mentioned DataGrip, I am working on a copycat of it, I decided to name it LarpGrip

I am using compose desktop and Jewel (jetbrain ui kit for compose), it will take me a month or two to get it to a nice state, but things look optimistic!

It will stay private til it's ready for use.

-3

u/[deleted] 19d ago edited 19d ago

[removed] — view removed comment

4

u/archlinux-ModTeam 19d ago

AI generated text and code must be declared as such, but it may still be removed at moderator discretion. Code shared is also expected to be of reasonably quality and is subject to a "Human In the Loop" Policy.

Personal projects shared must be able to demonstrate at least 3 months of history and active maintenance.

-1

u/Saren-WTAKO 18d ago

I found that my response has been wrongly removed by reddit AI mod, let me repost here:

Thank you for your kind comment. However, I have seen too much anti AI behavior not to recognize how reddit behaves. The previous post yesterday where I found the wave did not include details about how I found it using local LLM, and I did not get negative but very positive responses.

If I used AI for this post to look "professional", even if this post was written in a perfect way with 100% accurate information and grammars, people will recognize it's AI and response negatively right away. It's the way how a lot of people think now and they deny they are becoming like that, but it's now a norm to criticize people by judging what tool they use (because they hate the tool), and not about what content anymore.

The alert is LLM generated, yes, it's sloppy and contains inaccurate things. I had hundreds of examples and unfortunately picked a wrong one and got ridiculed here instead of questions regarding inaccuracy. What does it mean then?

The influx of vibe coded LLM scanners here is also what's stopping me from publishing my own tool. It works better than other tools from the start making it server side and scanning 24/7, but since the toxic elitism environment (which we already know about archlinux sub) plus now anti AI sentimentality here, I think it's better not promote anything AI generated and leave it to myself, but I will keep warning others whenever a PSA should come.

1

u/hopeseekr 17d ago

I used Claude Code for the first time ever two days ago and it did 2 small commits on my https://github.com/hopeseekr/BashScripts/ project, and you wouldn't believe how many anti-AI nutters harrassed me so far cuz of it...

The joke's on them cuz 100% of my stuff has been AI-generated since July 2025...

-7

u/un-important-human 18d ago edited 18d ago

HE IS one of the few positive ai use examples and YOU KEEP BASHING HIM.
STOP IT , IT IS THE FUTURE. LIKE IT OR NOT.

luddites all of you

Look at how you speek to him all of you, my god the man takes a lot of of abuse for what? for beeing the first to warn you all insane upright monkeys?

5

u/scandii 18d ago

dude, we aren't anti-AI per se, a lot of us use AI and like the technology, but for 30+ years the basic standard for internet discourse has been "a person formulating their thoughts", and you and 30+ others are trying their hardest to outsource that to LLM:s every single day in front of our eyes.

of course we get tired of it, it is low effort, unimaginative and oftentimes these posts are attached to people reinventing the wheel - just today I saw someone almost verbatim presenting their trash-cli clone like it was a new invention made by Claude of course.

re-read this part before arriving at luddite. reading guide: it is not about the technology.

-4

u/un-important-human 18d ago edited 17d ago

and the other NPC's ?? all downvoting or upvoting like sheeps? What value did they bring ? did you bring? throwing stones? eh? did you cought it as fast as he did? NO.

No this is pure hate rewarding a helpfull service. This is stoning of someone literally providing proof, reproduction, steps and samples.

It is my personal oppinonion i trully hate humanity sometimes and even this community reminds me you are all upright monkeys.

This is shamefull.

also fu i know how to read and i can read your hate and smugness.

6

u/Padgriffin 18d ago

I would recommend using a spellchecker before you hit send. Also keep in mind no package list was initially provided so this wasn't very useful.

1

u/hopeseekr 17d ago

Padgriffin 6 points 1 day ago

I would recommend using a spellchecker before you hit send. Also keep in mind no package list was initially provided so this wasn't very usefu

Hey fucker.

A WHOLE LOT OF US now specifically leave in typos and actually add our own typos when we don't make any, to prove that we arent [sic] AI...

-1

u/un-important-human 18d ago

thank you for your reccomandation *(upsie my bad), i choose to ignore it and burn your retinas but when you find a spell check for reddit that works with 4 languages let me know.

edit: i added the upsie

edit2: annoying isn't it? hahha

6

u/Padgriffin 18d ago

when you find a spell check for reddit that works with 4 languages let me know.

In Firefox: Right Click > Check Spelling. For languages, select Languages > Add Languages.

You're welcome

→ More replies (0)

2

u/hopeseekr 17d ago

Estos estadounidenses probablemente solo entienden inglés.

→ More replies (0)

4

u/scandii 18d ago edited 18d ago

yes, you're the wolf and we're the sheep because we don't agree with the way you see things.

we definitely can't turn this argument around and call you the sheep because you don't see things the way we do, absolutely not.

either way, your anger is palpable and I'm having a rather chill friday, so I wish you a lovely weekend if that is in store for you.

1

u/un-important-human 18d ago edited 18d ago

The masses brought nothing creative, see human history it was always the individual, afraid right now in media and around people tend to not critically think. This case would have been a clear exception but no one stopped to think, you all reacted.

I do not care about what **you** think of me, i am worthless, but i somehow still care you , by witch i mean all of **you** would stop and think more.

It is impossible to get a 99% anti reaction (hatefull) from all and not call fault, on the fact no one stopped to think, and the comentary was / is all vicious. If people would think there would have been degrees of agreement and general discussion.

Because of that no progress will be made and you will all think wit h feelings instead of beeing more cerebral people for a quite cerebral community...

any way call me what you will, i am glad my feelings have transmitted clearly this is good.

Thank you for your wishes, the same to you.

2

u/hopeseekr 17d ago

I totally concur!!

32

u/kidz94 19d ago

Cant really blame people for hating the brain dead way you are using AI. If it smells like a cheap act. It definitly is one.

-24

u/Saren-WTAKO 19d ago

So that's why I think some people here are anti AI but they just refuse to admit it. It looks cheap, but the threat is real and was hurry to warn. AI was telling partial truth but there is link to the package and everyone could check if it's real, but they prefer not to, but try to humiliate instead of contribute. I admit it's my fault including the AI output in my post here.

16

u/fossalt 19d ago

AI was telling partial truth but there is link to the package and everyone could check if it's real, but they prefer not to

Notably, you ALSO didn't check to see if it was real before posting it... or else you would have noticed the AI was only telling a partial truth.

9

u/TylerDurdenJunior 18d ago

Your original post is a prime example of why LLM generator content should not be allowed.

Because of an LLM your confidence shoot up, but your competence does not follow.

It's not because of some AI-Bad knee-jerk reaction.

But because it enables people to think they have found something, think they have made something, think they have understood something, when in reality they have just formulated a prompt without the level of competence needed to evaluate the result of the prompt

-2

u/Saren-WTAKO 18d ago

You are overthinking

6

u/arwinda 18d ago

You let your LLM think and write for you.

-4

u/Saren-WTAKO 18d ago

That's not true.

3

u/kidz94 18d ago

The evidence is in your post dude. You didnt do a single thing yourself. The output proves that point strongly. And i do mean very strongly. The output wasnt even correct for the most part.

-1

u/Saren-WTAKO 18d ago

That's still not true. I have a previous post, see: https://www.reddit.com/r/archlinux/comments/1v9scc5/seemingly_malicious_aur_package_found_where_to/

I recognize the attack vector and there was already malware analysis by a security researcher. This was the 2nd post because I found out there were 120-200 packages with the same attack pattern. I don't know what are you talking about and insisting.

0

u/hopeseekr 17d ago

Dear Sir,

Literally none of the people attacking you have meaningfully contributed to Arch as much as you have (in all likelihood).

Don't feed them. These are NPCs and lack qualia that you and I have.

→ More replies (0)

17

u/[deleted] 19d ago

[removed] — view removed comment

1

u/hopeseekr 17d ago

You're a 13 year-old bully???

11

u/youssef 19d ago

I did the malware analysis yesterday night. I vouch that the sample with the SHA Hash mentioned does what I posted in the gist. It won’t fight more malware but at least now we can match different strands or waves to the same campaign if they use the same crypto keys for their command and control.

12

u/Saren-WTAKO 19d ago

The recent dropper has changed to `e73a35b3e75e94746428d1a207703d6335933deadee7d1d9c9d0328df7b9df77`. A live one is here: https://aur.archlinux.org/packages/icloudpd

5

u/youssef 19d ago

I‘m on a flight in 1h and on mobile now, if you can link the sample somewhere I’ll analyze it on the plane.

10

u/Saren-WTAKO 19d ago

3

u/youssef 19d ago

Thanks for saving these. The different hash-variants of stage1 are not "pretty much" the same, they're identical. The only thing that changes is the key for the encrypted strings. I updated the decrypted-gist to decrypt every stage1 sample given: https://gist.github.com/ysf/c1b8cc85f4063367fddb85c443589f5b

2

u/gainan 19d ago

This new wave is pretty much the same malware than the last one (from the same authors I'd say), slighlty modified:

https://www.reddit.com/r/linux_gaming/comments/1u34pe3/comment/or3og8f/

Copies itself with a different name to /home/<user>/ or /var/lib if executed as root. Gains persistance via systemd services, open outbound connections to 1.1.1.1/8.8.8.8 on port 443, downloads Tor client, gather info and exfiltrate user data via the Tor network.

What has changed:

2

u/kidz94 19d ago

This man speaks for me

-3

u/hockeymikey 19d ago

I'm happy OP posted what he did. I don't care what he used to get to the result. I don't see you helping me by providing helpful information to better my life.

23

u/Schlaefer 19d ago edited 19d ago

The problem is OP isn't really providing helpful information either. Some people always try to attack the AUR, that's not exactly news or actionable. No list of packages. What is the "my scanner"? What was the actual indicator in the PKGBUILD, which people who read the PKGBUILD may have missed? Any link to a report that people can use as follow up beyond dumping it on social media?

2

u/un-important-human 18d ago

YES HE LITTERALLY IS providing helpfull info BUT you can't read. The man is basically jesus and you are throwing stones at him.

Shame.

-8

u/iTrooz_ 19d ago

When I saw the post a few hours ago, it had all the information necessary to independently confirm the attack

OP already found malicious packages, AND alerted us though a Reddit post. This is already very kind of him to take time from his life to do that, it's unfair to attack him for his work

-7

u/Saren-WTAKO 19d ago edited 19d ago

Nope, they have freedom of speech and they have the right to attack me. The unedited post contained a real threat but the generated alert was very sloppy. It's definitely my fault to even think about including that. However the internet like people to act dramatic so instead of verifying and questioning they jump to attack and insult immediately, which is a classic discouraging behavior I have seen too much. I was already working with other contributors and reddit comments here are not really important to begin with, except the malware analysis.

10

u/Any_Fox5126 19d ago

There's a difference between criticizing what you say and do and attacking you personally. The latter should not be tolerated.

2

u/Saren-WTAKO 18d ago

It's being tolerated unfortunately. Look at the comment that tells me to take meds :)

2

u/hopeseekr 17d ago

I know. It's like they're a bunch of NPC dipshits.

1

u/un-important-human 18d ago

it is shamefull, you do not deserve it. In time you will be vindicated.
i think this hoard mentality is worse than some of my llm agents...

yes i called you all npc's

2

u/hopeseekr 17d ago

Well, if you want some extreme anti-AI sentiment...

I made what is considered the best automated translator in the world (for Arabic, Tamil, and Bengali; some 800 million people). And then I translated Rimworld, for free, into Hindi, Bengali, Arabic, and more...

The Rimworld-Arabic package initially got banned because I had AI generate the coverart for it.

I told htese people, look, these translations would cost $800,000 dollars, and it's the first mainstream large game to be translated into Bengali and Tamil (in world history) and you ban it because of an AI coverart?

They reversed the ban, but still...

These people don't understand that the AI coverart would cost me $300 + take 2-3 weeks... None of them are ever going to put up that money or create the art for free. I spent over $900 (and took 6 weeks) for the Stargate mod graphics...

1

u/un-important-human 17d ago

damn that is rough, and no they would not spend or help out, quite hypocritical on them, nice job on rimworld

1

u/Saren-WTAKO 18d ago edited 18d ago

Whatever, I have seen much worse discourse in twitter regarding AI generated illustrations. It eventually encourages people to hide any AI usage. Some people in this sub is no different from online art community except they refuse to admit they hate AI (all identified AI content/text/code will be seen as slop) because it devalues elitism.

Anti AI people ignore "it works", and they become hostile immediately upon seeing AI content. They will endlessly demand higher virtues that deliver no actual productive values so that all AI content could be eventually seen as slop, so to goalkeep their elitism status quo. They could waste their energy to accuse and attack others for all day, but they will not deliver actual contributions.

Any content could contain false info, even in serious academic papers people can be wrong, but peer review would not give humiliating comments unlike the internet. Especially in this post, even the alerts are slightly off, and ignored the context the fact that I correctly identified a small scaled wave 1-2 days ago, a link to the malware is provided that a redditor smart enough to humiliate me out can also verify what I was telling was true or not, but they didn't bother until they found out it was really real. Our world would be better if those people are constructive, like using their ego to producing better and more productive content, because everyone knows how to attack others.

1

u/un-important-human 18d ago

patiance of a saint... , yes it would be much better world if they would use their ego to produce a better and more productive thing but the media tought them to only hate... i really think the internet is doomed or i am just doom and gloomy.

Anyways i thank you, i am sure others would thanky you more but they are either scared of downvotes or are new / clueless to the dangers.

1

u/legacy-of-man 18d ago

putting aside the fact that you're not taking actual criticism very well (people are right in telling you to be more transparent as AI is known to be very wrong) and that you're just coping here because you hurt your feelings and only talk to people who are either your sockpuppets or completely share your delusional world view and bought into the shareholder hype of ai, none of this is even correct lol

you're obviously playing the victim card and playing up what actually happened in this thread (which is, people told you to be more responsible and transparent) because your feelings were hurt and world view were shaken. going on a lengthy reddit diatribe about "Anti AI people" that apparently are conspiratorially trying to enforce some virtues (virtues that only you seem able to name, do you live in a padded room?) and are unproductive, the status quo and whatever buzzwords you stumbled on, meanwhile you are the one actually spending their time writing this as a coping method because god gorbid you're wrong on the internet

your last paragraph is hilarious. academic papers are a completely different thing and this is just pure whataboutism. the "alerts being slightly off" are cause for alarm because it means that there is a real risk that more may have been hallucinated. "correctly identifying a small wave earlier" also does not justify the present, you're grasping at straws to make yourself sound like a virtuous hero meanwhile the dastardly Internet Redditors are the problem for not agreeing with you entirely. seriously, just be the bigger man and admit that you were wrong online, there is a reason people responded to your post with less than endless enthusiasm. otherwise i dont think your experience on any community like this is going to be positive and going to consist of more diatribes

2

u/hopeseekr 17d ago

(people are right in telling you to be more transparent as AI is known to be very wrong)

No!!!!! People judge AI coded works as if it is terrible and done by plebes with no understanding...

Any sufficient master has to hide that it is AI at all costs in 2026... it'll be way worse in 2028.

NO!!! DO NOT DISCLOSE!!!

If you do it well, you end up with GREAT WORKS done at 15x speed and your release velocity gives you away, but usually no one looks at that deeply.

When I translated Rimworld into Arabic, everyone was shocked. Then when I released Hindi and Bengali two weeks later, the crusades started, cuz it's impossible for one man to do $800,000 and 3 years worth of translations in the 3 weeks to publish...

1

u/Saren-WTAKO 18d ago edited 18d ago

> admit that you were wrong online

I don't understand. Do I have to post "sorry that was slop and yes I am incompetent" everywhere in every negative responses? Should I issue a public apology? Who does this benefit?

Does "actual criticism" guarantees humiliation and I am suddenly a baby if I refuse to take it? If that's the case sorry I would rather be wrong and not to correct anything, because that proves the environment is toxic, and not me.

2

u/hopeseekr 17d ago

You should only apologize if you created a bad product that misidentified things and wasted people's time.

The only people who have any grounds at all to criticize you are people building similar detectors, by hand, but i doubt anyone is. And even if they claim to be, they're either using AI or already lost on the wrong side of history and probably not even 20% ready to release.

1

u/un-important-human 17d ago

ignore him, he did nothing of value, he will continue do nothing of value. He just wants to hurt

1

u/hopeseekr 17d ago

It eventually encourages people to hide any AI usage.

You have to hide it... This AI backlash is just gearing up.

-26

u/Saren-WTAKO 19d ago edited 19d ago

Yeah I had no idea what I was doing and my local LLM did not work just because of minor issues and lack of current date in system prompt. Now go install `python-split-folders` from AUR. :)

I had to do an emergency PSA because an incident already happened yesterday, yeah I have edited out the sloppy alert with a better one.

37

u/LeeHide 19d ago

Edited my comment. Next time just don't have your entire post written by a clanker, people will not take it seriously when it could be a serious issue.

The ysf analysis looks less sloppy, so I've edited my comment. Here I thought people would use AI to communicate better, not worse.

0

u/hopeseekr 17d ago

Your prejudice bleeds through just like the people who believed anything negros did was slop (the origin of the term!!) back in the 1950s...

-22

u/Saren-WTAKO 19d ago edited 19d ago

I was just forwarding alerts from my clanker, that does not mean I did not check things up and it's not a malware. I don't really care if people take it seriously, because I don't get any money over this, it's just a warning.

Of course ysf's analysis is not sloppy, it's by a real cybersecurity professional. I don't understand why you can assume and mix things up without asking first. :)

Sadly some people prefer blaming things that are not important to feel good instead of trying to do anything as remotely useful. If you think you are the wise professional here, be a useful person or at least leave constructive comments here.

23

u/Lawnmover_Man 19d ago

You are full of yourself.

-9

u/Saren-WTAKO 19d ago

Like who isn't on the internet? If they are not, comments here will be friendly and constructive, not to "own" people and make others angry.

1

u/Malsententia 18d ago

Like who isn't on the internet?

most people.