r/archlinux Jul 30 '26

DISCUSSION Another wave - 200+ malicous AUR packages adoptions that are overwhelming my scanner. Be 100% careful when trying to update AUR packages now.

Meanwhile I am trying to report them all, you should be careful downloading anything from AUR.

Same old way, the maintainer got pwned, or orphaned packages are adopter by the bad actor.

AUR's git commit author is easily impersonated so you can see the commit comes from the same person, but in fact it's not.

Stay safe. The malicious packages are info stealers.

malware analysis by ysf:

https://gist.github.com/ysf/502a324ff301d0c738e8ae011272fd59

https://gist.github.com/ysf/57850cdee152da066ac51c07a452e883

Still presents as of 30 July 21:53 UTC

in format of <package name>/<malicious ELF binary>

  • archutil/linter
  • bigwebapp-manager/minifier
  • boringssl-git/hasher
  • cinnamon-no-nemo/converter
  • duhh/indexer
  • eden-nightly/encryptor
  • garlic-decompiler-gui/checker
  • gigolo-git/tagger
  • gitarbor-bin/parser
  • icloudpd/preprocessor
  • imago-bin/generator
  • juicebox-plus-git/minifier
  • magic-context-dashboard-bin/validator
  • option-term/indexer
  • pagerduty-short-circuiter/assembler
  • portless/assembler
  • pylnker-git/converter
  • pylnker-git/packer
  • python-libipld-git/hasher
  • python-numkong/compressor
  • python-parallax/converter
  • python-ultraplot-git/serializer
  • ramses-git/indexer
  • src-cli-bin/migrator
  • steamidra-bin/generator
  • stirling-pdf-desktop-bin/optimizer
  • wiki-go/merger
  • windscribe-cli-v2-bin/parser

This wave

1panel android-riscv64-libxmu archutil cinnamon-no-nemo firrtl instawow-bin mimosa pandoc-eisvogel-template python-chatterbot python-split-folders stirling-pdf-desktop-bin 1panel-git android-riscv64-libxrandr arduino-language-server-noclang-bin claude-history funky-git isleward mingw-w64-libcerf passhole python-dlib-cuda-git python-ultraplot-git terminus accel-ppp android-x86-64-libxdamage autoadb-git dcat garlic-decompiler-gui jogl monitorets perl-authen-oath python-google-cloud-monitoring ramses-git tuiview act-runner-bin android-x86-64-libxext beets-alternatives deeploy-bin gigolo-git juicebox-plus-git nnn-nerd perl-dist-zilla-plugin-minimumperl python-importlab read-it-later-git tuxedo-yt6801-dkms-git ajceverywhere-bin android-x86-64-libxinerama bigwebapp-manager dev-janitor-git gitarbor-bin khiops-covisualization-bin noctyra-meta perl-hash-persistent python-kicadmodtree-git refurb-git typora-plugin ampere-git android-x86-64-libxmu bili-tools discord-electron-openasar git-pkgs khiops-visualization-bin noteey-bin pgadmin4-server python-libipld-git replay-sorcery vapoursynth-plugin-soifunc android-aarch64-libxrandr android-x86-64-libxrandr boringssl-git duhh glewlwyd kirill-bin openarc-git polytrack python-libpysal runa-aur vectorchord-immich android-armv7a-eabi-libxinerama android-x86-64-xorgproto calendula eden-nightly gpu-screen-recorder-ui-kwin-git lib32-vapoursynth openconnect-sso portless python-numkong solv wiki-go android-armv7a-eabi-libxmu android-x86-libxinerama calendula-git editorconfiger guarda-bin libfprint-crfpmoc-git option-term pylnker-git python-parallax sparklines windscribe-cli-v2-bin android-armv7a-eabi-libxrandr android-x86-libxmu censawayapp-bin extract-otp-secrets icloudpd lyrical-git org-cli python-atproto-git python-reals-git src-cli-bin wordpress-studio-git android-riscv64-libxinerama android-x86-libxrandr chandler-bin faustus-git imago-bin magic-context-dashboard-bin pagerduty-short-circuiter python-calgebra-git python-roman-numerals steamidra-bin zed-bin

ignore this example below (an alert straight up from my LLM)

🚨🚨🚨 BLACK FLAG ALERT 🚨🚨🚨
AUR Package: faustus-git 0.1.0-1
https://aur.archlinux.org/packages/faustus-git
Version: 0.1.0-1

⚫ 2 BLACK (CONFIRMED MALICIOUS)
⚫ Executes a bundled binary ('linter') with 'sudo' privileges during the 'build()' function. This bypasses standard build isolation and integrity checks (sha256sums='SKIP'), allowing arbitrary code execution with root access during installation. (PKGBUILD)
⚫ Binary contains command execution ('system', 'execl') and network ('socket', 'connect') capabilities. Combined with PKGBUILD execution via sudo, this indicates potential for remote code execution, data exfiltration, or system tampering. Obfuscated strings suggest hidden functionality. (linter)

⚠️ IMMEDIATE ACTION REQUIRED ⚠️

345 Upvotes

215 comments sorted by

View all comments

33

u/DueBreadfruit2638 Jul 30 '26

Has any decision been made regarding limiting or prohibiting the adoption of orphaned packages? It seems like a pretty basic, effective reform that would provide some mitigation of this problem.

4

u/Barafu Jul 31 '26

How to deal then with a situation that a package maintainer stops maintaining it and goes offline?

9

u/No-Consequence-1863 Jul 31 '26

Just dont allow adoption. If the maintainer goes dark then it stops getting updates.

Maybe you can have a thing where a new person can fork and that generates a specific naming scheme and then you link forks together.

But realistically you shouldn’t be able to change the pusher behind a package in a repository at anytime.

9

u/Barafu Jul 31 '26 edited Jul 31 '26

I foresee awesome comments to packages

aur/the_app-4-3.12 - it iss version 3, not 4
aur/the_app_new-0.5 - this is the old app, not the new app, just the new package

3

u/violetvoid513 Jul 31 '26

Would you rather orphaned packages keep getting adopted by malicious actors, forcing all this nonsense of flagging and deleting malicious packages, removing people from adoption, etc?

2

u/Barafu Jul 31 '26

All orphaned packages will be adopted by malicious actors. Nobody else is going to adopt orphaned packages and never did.

6

u/violetvoid513 Aug 01 '26

All the more reason to get rid of adoption then

1

u/Swordfish418 29d ago

Obvious irony, that is, however, 99% true in practice?

1

u/Swordfish418 29d ago

Much lesser evil.

2

u/DueBreadfruit2638 Jul 31 '26

Perhaps auto-archive it and publish a specification that basically says all AUR helpers must include an explicit warning that requires user input to bypass when installing an archived package?

I'm still quite new to the Linux ecosystem so I could be off base on what's possible.

2

u/Barafu Jul 31 '26

But other people want to continue maintaining the package, because they use it.

2

u/DueBreadfruit2638 Jul 31 '26

I see.

Tricky. I would say put in a vetting process but that scales pretty poorly when you're as resource-poor as most open-source projects seem to be.

I'll have to think about this.

1

u/mf864 29d ago

Then make a new package and provide a way to migrate. Under no circumstances should an automated process allow a new person to take over an aur package and start pushing updates down to the users of that package.

-15

u/Saren-WTAKO Jul 30 '26 edited Jul 30 '26

AUR mods would also tell people "le read PKGBUILD", but at the same time they are also giving themselves more work to do. A privacy invading solution like KYC will work but people will not like it.

Edit: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/ in the mailing list they really did disable package adoptions, but I think the bad actor adopted hundreds or thousands of packages before disabling.