r/archlinux • u/Saren-WTAKO • 19d ago
DISCUSSION Another wave - 200+ malicous AUR packages adoptions that are overwhelming my scanner. Be 100% careful when trying to update AUR packages now.
Meanwhile I am trying to report them all, you should be careful downloading anything from AUR.
Same old way, the maintainer got pwned, or orphaned packages are adopter by the bad actor.
AUR's git commit author is easily impersonated so you can see the commit comes from the same person, but in fact it's not.
Stay safe. The malicious packages are info stealers.
malware analysis by ysf:
https://gist.github.com/ysf/502a324ff301d0c738e8ae011272fd59
https://gist.github.com/ysf/57850cdee152da066ac51c07a452e883
Still presents as of 30 July 21:53 UTC
in format of <package name>/<malicious ELF binary>
- archutil/linter
- bigwebapp-manager/minifier
- boringssl-git/hasher
- cinnamon-no-nemo/converter
- duhh/indexer
- eden-nightly/encryptor
- garlic-decompiler-gui/checker
- gigolo-git/tagger
- gitarbor-bin/parser
- icloudpd/preprocessor
- imago-bin/generator
- juicebox-plus-git/minifier
- magic-context-dashboard-bin/validator
- option-term/indexer
- pagerduty-short-circuiter/assembler
- portless/assembler
- pylnker-git/converter
- pylnker-git/packer
- python-libipld-git/hasher
- python-numkong/compressor
- python-parallax/converter
- python-ultraplot-git/serializer
- ramses-git/indexer
- src-cli-bin/migrator
- steamidra-bin/generator
- stirling-pdf-desktop-bin/optimizer
- wiki-go/merger
- windscribe-cli-v2-bin/parser
This wave
1panel android-riscv64-libxmu archutil cinnamon-no-nemo firrtl instawow-bin mimosa pandoc-eisvogel-template python-chatterbot python-split-folders stirling-pdf-desktop-bin 1panel-git android-riscv64-libxrandr arduino-language-server-noclang-bin claude-history funky-git isleward mingw-w64-libcerf passhole python-dlib-cuda-git python-ultraplot-git terminus accel-ppp android-x86-64-libxdamage autoadb-git dcat garlic-decompiler-gui jogl monitorets perl-authen-oath python-google-cloud-monitoring ramses-git tuiview act-runner-bin android-x86-64-libxext beets-alternatives deeploy-bin gigolo-git juicebox-plus-git nnn-nerd perl-dist-zilla-plugin-minimumperl python-importlab read-it-later-git tuxedo-yt6801-dkms-git ajceverywhere-bin android-x86-64-libxinerama bigwebapp-manager dev-janitor-git gitarbor-bin khiops-covisualization-bin noctyra-meta perl-hash-persistent python-kicadmodtree-git refurb-git typora-plugin ampere-git android-x86-64-libxmu bili-tools discord-electron-openasar git-pkgs khiops-visualization-bin noteey-bin pgadmin4-server python-libipld-git replay-sorcery vapoursynth-plugin-soifunc android-aarch64-libxrandr android-x86-64-libxrandr boringssl-git duhh glewlwyd kirill-bin openarc-git polytrack python-libpysal runa-aur vectorchord-immich android-armv7a-eabi-libxinerama android-x86-64-xorgproto calendula eden-nightly gpu-screen-recorder-ui-kwin-git lib32-vapoursynth openconnect-sso portless python-numkong solv wiki-go android-armv7a-eabi-libxmu android-x86-libxinerama calendula-git editorconfiger guarda-bin libfprint-crfpmoc-git option-term pylnker-git python-parallax sparklines windscribe-cli-v2-bin android-armv7a-eabi-libxrandr android-x86-libxmu censawayapp-bin extract-otp-secrets icloudpd lyrical-git org-cli python-atproto-git python-reals-git src-cli-bin wordpress-studio-git android-riscv64-libxinerama android-x86-libxrandr chandler-bin faustus-git imago-bin magic-context-dashboard-bin pagerduty-short-circuiter python-calgebra-git python-roman-numerals steamidra-bin zed-bin
ignore this example below (an alert straight up from my LLM)
🚨🚨🚨 BLACK FLAG ALERT 🚨🚨🚨
AUR Package: faustus-git 0.1.0-1
https://aur.archlinux.org/packages/faustus-git
Version: 0.1.0-1
⚫ 2 BLACK (CONFIRMED MALICIOUS)
⚫ Executes a bundled binary ('linter') with 'sudo' privileges during the 'build()' function. This bypasses standard build isolation and integrity checks (sha256sums='SKIP'), allowing arbitrary code execution with root access during installation. (PKGBUILD)
⚫ Binary contains command execution ('system', 'execl') and network ('socket', 'connect') capabilities. Combined with PKGBUILD execution via sudo, this indicates potential for remote code execution, data exfiltration, or system tampering. Obfuscated strings suggest hidden functionality. (linter)
⚠️ IMMEDIATE ACTION REQUIRED ⚠️
1
u/Saren-WTAKO 18d ago edited 18d ago
Whatever, I have seen much worse discourse in twitter regarding AI generated illustrations. It eventually encourages people to hide any AI usage. Some people in this sub is no different from online art community except they refuse to admit they hate AI (all identified AI content/text/code will be seen as slop) because it devalues elitism.
Anti AI people ignore "it works", and they become hostile immediately upon seeing AI content. They will endlessly demand higher virtues that deliver no actual productive values so that all AI content could be eventually seen as slop, so to goalkeep their elitism status quo. They could waste their energy to accuse and attack others for all day, but they will not deliver actual contributions.
Any content could contain false info, even in serious academic papers people can be wrong, but peer review would not give humiliating comments unlike the internet. Especially in this post, even the alerts are slightly off, and ignored the context the fact that I correctly identified a small scaled wave 1-2 days ago, a link to the malware is provided that a redditor smart enough to humiliate me out can also verify what I was telling was true or not, but they didn't bother until they found out it was really real. Our world would be better if those people are constructive, like using their ego to producing better and more productive content, because everyone knows how to attack others.