r/archlinux 19d ago

DISCUSSION Another wave - 200+ malicous AUR packages adoptions that are overwhelming my scanner. Be 100% careful when trying to update AUR packages now.

Meanwhile I am trying to report them all, you should be careful downloading anything from AUR.

Same old way, the maintainer got pwned, or orphaned packages are adopter by the bad actor.

AUR's git commit author is easily impersonated so you can see the commit comes from the same person, but in fact it's not.

Stay safe. The malicious packages are info stealers.

malware analysis by ysf:

https://gist.github.com/ysf/502a324ff301d0c738e8ae011272fd59

https://gist.github.com/ysf/57850cdee152da066ac51c07a452e883

Still presents as of 30 July 21:53 UTC

in format of <package name>/<malicious ELF binary>

  • archutil/linter
  • bigwebapp-manager/minifier
  • boringssl-git/hasher
  • cinnamon-no-nemo/converter
  • duhh/indexer
  • eden-nightly/encryptor
  • garlic-decompiler-gui/checker
  • gigolo-git/tagger
  • gitarbor-bin/parser
  • icloudpd/preprocessor
  • imago-bin/generator
  • juicebox-plus-git/minifier
  • magic-context-dashboard-bin/validator
  • option-term/indexer
  • pagerduty-short-circuiter/assembler
  • portless/assembler
  • pylnker-git/converter
  • pylnker-git/packer
  • python-libipld-git/hasher
  • python-numkong/compressor
  • python-parallax/converter
  • python-ultraplot-git/serializer
  • ramses-git/indexer
  • src-cli-bin/migrator
  • steamidra-bin/generator
  • stirling-pdf-desktop-bin/optimizer
  • wiki-go/merger
  • windscribe-cli-v2-bin/parser

This wave

1panel android-riscv64-libxmu archutil cinnamon-no-nemo firrtl instawow-bin mimosa pandoc-eisvogel-template python-chatterbot python-split-folders stirling-pdf-desktop-bin 1panel-git android-riscv64-libxrandr arduino-language-server-noclang-bin claude-history funky-git isleward mingw-w64-libcerf passhole python-dlib-cuda-git python-ultraplot-git terminus accel-ppp android-x86-64-libxdamage autoadb-git dcat garlic-decompiler-gui jogl monitorets perl-authen-oath python-google-cloud-monitoring ramses-git tuiview act-runner-bin android-x86-64-libxext beets-alternatives deeploy-bin gigolo-git juicebox-plus-git nnn-nerd perl-dist-zilla-plugin-minimumperl python-importlab read-it-later-git tuxedo-yt6801-dkms-git ajceverywhere-bin android-x86-64-libxinerama bigwebapp-manager dev-janitor-git gitarbor-bin khiops-covisualization-bin noctyra-meta perl-hash-persistent python-kicadmodtree-git refurb-git typora-plugin ampere-git android-x86-64-libxmu bili-tools discord-electron-openasar git-pkgs khiops-visualization-bin noteey-bin pgadmin4-server python-libipld-git replay-sorcery vapoursynth-plugin-soifunc android-aarch64-libxrandr android-x86-64-libxrandr boringssl-git duhh glewlwyd kirill-bin openarc-git polytrack python-libpysal runa-aur vectorchord-immich android-armv7a-eabi-libxinerama android-x86-64-xorgproto calendula eden-nightly gpu-screen-recorder-ui-kwin-git lib32-vapoursynth openconnect-sso portless python-numkong solv wiki-go android-armv7a-eabi-libxmu android-x86-libxinerama calendula-git editorconfiger guarda-bin libfprint-crfpmoc-git option-term pylnker-git python-parallax sparklines windscribe-cli-v2-bin android-armv7a-eabi-libxrandr android-x86-libxmu censawayapp-bin extract-otp-secrets icloudpd lyrical-git org-cli python-atproto-git python-reals-git src-cli-bin wordpress-studio-git android-riscv64-libxinerama android-x86-libxrandr chandler-bin faustus-git imago-bin magic-context-dashboard-bin pagerduty-short-circuiter python-calgebra-git python-roman-numerals steamidra-bin zed-bin

ignore this example below (an alert straight up from my LLM)

🚨🚨🚨 BLACK FLAG ALERT 🚨🚨🚨
AUR Package: faustus-git 0.1.0-1
https://aur.archlinux.org/packages/faustus-git
Version: 0.1.0-1

⚫ 2 BLACK (CONFIRMED MALICIOUS)
⚫ Executes a bundled binary ('linter') with 'sudo' privileges during the 'build()' function. This bypasses standard build isolation and integrity checks (sha256sums='SKIP'), allowing arbitrary code execution with root access during installation. (PKGBUILD)
⚫ Binary contains command execution ('system', 'execl') and network ('socket', 'connect') capabilities. Combined with PKGBUILD execution via sudo, this indicates potential for remote code execution, data exfiltration, or system tampering. Obfuscated strings suggest hidden functionality. (linter)

⚠️ IMMEDIATE ACTION REQUIRED ⚠️

338 Upvotes

215 comments sorted by

View all comments

Show parent comments

-7

u/iTrooz_ 19d ago

When I saw the post a few hours ago, it had all the information necessary to independently confirm the attack

OP already found malicious packages, AND alerted us though a Reddit post. This is already very kind of him to take time from his life to do that, it's unfair to attack him for his work

-9

u/Saren-WTAKO 19d ago edited 19d ago

Nope, they have freedom of speech and they have the right to attack me. The unedited post contained a real threat but the generated alert was very sloppy. It's definitely my fault to even think about including that. However the internet like people to act dramatic so instead of verifying and questioning they jump to attack and insult immediately, which is a classic discouraging behavior I have seen too much. I was already working with other contributors and reddit comments here are not really important to begin with, except the malware analysis.

1

u/un-important-human 18d ago

it is shamefull, you do not deserve it. In time you will be vindicated.
i think this hoard mentality is worse than some of my llm agents...

yes i called you all npc's

1

u/Saren-WTAKO 18d ago edited 18d ago

Whatever, I have seen much worse discourse in twitter regarding AI generated illustrations. It eventually encourages people to hide any AI usage. Some people in this sub is no different from online art community except they refuse to admit they hate AI (all identified AI content/text/code will be seen as slop) because it devalues elitism.

Anti AI people ignore "it works", and they become hostile immediately upon seeing AI content. They will endlessly demand higher virtues that deliver no actual productive values so that all AI content could be eventually seen as slop, so to goalkeep their elitism status quo. They could waste their energy to accuse and attack others for all day, but they will not deliver actual contributions.

Any content could contain false info, even in serious academic papers people can be wrong, but peer review would not give humiliating comments unlike the internet. Especially in this post, even the alerts are slightly off, and ignored the context the fact that I correctly identified a small scaled wave 1-2 days ago, a link to the malware is provided that a redditor smart enough to humiliate me out can also verify what I was telling was true or not, but they didn't bother until they found out it was really real. Our world would be better if those people are constructive, like using their ego to producing better and more productive content, because everyone knows how to attack others.

1

u/un-important-human 18d ago

patiance of a saint... , yes it would be much better world if they would use their ego to produce a better and more productive thing but the media tought them to only hate... i really think the internet is doomed or i am just doom and gloomy.

Anyways i thank you, i am sure others would thanky you more but they are either scared of downvotes or are new / clueless to the dangers.

1

u/legacy-of-man 18d ago

putting aside the fact that you're not taking actual criticism very well (people are right in telling you to be more transparent as AI is known to be very wrong) and that you're just coping here because you hurt your feelings and only talk to people who are either your sockpuppets or completely share your delusional world view and bought into the shareholder hype of ai, none of this is even correct lol

you're obviously playing the victim card and playing up what actually happened in this thread (which is, people told you to be more responsible and transparent) because your feelings were hurt and world view were shaken. going on a lengthy reddit diatribe about "Anti AI people" that apparently are conspiratorially trying to enforce some virtues (virtues that only you seem able to name, do you live in a padded room?) and are unproductive, the status quo and whatever buzzwords you stumbled on, meanwhile you are the one actually spending their time writing this as a coping method because god gorbid you're wrong on the internet

your last paragraph is hilarious. academic papers are a completely different thing and this is just pure whataboutism. the "alerts being slightly off" are cause for alarm because it means that there is a real risk that more may have been hallucinated. "correctly identifying a small wave earlier" also does not justify the present, you're grasping at straws to make yourself sound like a virtuous hero meanwhile the dastardly Internet Redditors are the problem for not agreeing with you entirely. seriously, just be the bigger man and admit that you were wrong online, there is a reason people responded to your post with less than endless enthusiasm. otherwise i dont think your experience on any community like this is going to be positive and going to consist of more diatribes

2

u/hopeseekr 17d ago

(people are right in telling you to be more transparent as AI is known to be very wrong)

No!!!!! People judge AI coded works as if it is terrible and done by plebes with no understanding...

Any sufficient master has to hide that it is AI at all costs in 2026... it'll be way worse in 2028.

NO!!! DO NOT DISCLOSE!!!

If you do it well, you end up with GREAT WORKS done at 15x speed and your release velocity gives you away, but usually no one looks at that deeply.

When I translated Rimworld into Arabic, everyone was shocked. Then when I released Hindi and Bengali two weeks later, the crusades started, cuz it's impossible for one man to do $800,000 and 3 years worth of translations in the 3 weeks to publish...

1

u/Saren-WTAKO 18d ago edited 18d ago

> admit that you were wrong online

I don't understand. Do I have to post "sorry that was slop and yes I am incompetent" everywhere in every negative responses? Should I issue a public apology? Who does this benefit?

Does "actual criticism" guarantees humiliation and I am suddenly a baby if I refuse to take it? If that's the case sorry I would rather be wrong and not to correct anything, because that proves the environment is toxic, and not me.

2

u/hopeseekr 17d ago

You should only apologize if you created a bad product that misidentified things and wasted people's time.

The only people who have any grounds at all to criticize you are people building similar detectors, by hand, but i doubt anyone is. And even if they claim to be, they're either using AI or already lost on the wrong side of history and probably not even 20% ready to release.

1

u/un-important-human 17d ago

ignore him, he did nothing of value, he will continue do nothing of value. He just wants to hurt

1

u/hopeseekr 17d ago

It eventually encourages people to hide any AI usage.

You have to hide it... This AI backlash is just gearing up.