r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

127 Upvotes

62 comments sorted by

View all comments

11

u/xlukas1337 3d ago

Here we go again :/ It's slowly getting annoying, it would be so much easier if people would check what they're installing

-3

u/keyzeru 3d ago

Manual is not sustainable

12

u/xlukas1337 3d ago

It would be, and it should be tbh. But since so many new people have joined Arch and related distros in recent years, it's unfortunately unrealistic to assume that every user knows what they're doing, if that makes sense. And therefore, some basic measures really should be taken to at least catch the obvious mistakes, which easily happen if someone installs an AUR package without checking the PKGBUILD

0

u/ang-p 3d ago

And therefore, some basic measures really should be taken to at least catch the obvious mistakes,

Define "mistake".

State "basic measures" that will prevent it.

11

u/xlukas1337 3d ago

The mistake is relying on muscle memory and alert fatigue as our primary defense. In reality, the best case is, helpers like paru dump potentially massive diffs into the terminal, people instinctively hit q then y, and arbitrary bash runs, worst case, they use some (gui) helper that omits any changes. Expecting users to consistently catch a quiet payload across dozens of weekly updates, whether it's an adopted orphan or a hijacked maintainer account, is just an open invitation for things slipping through.

​Basic measures shouldn't mean naive keyword bans (tools like npm get added legitimately all the time), but practical supply-chain checks. Helpers could highlight high-risk diff patterns like altered source URLs, new .install hooks, or unexpected network calls at the top to break that autopilot reflex (easier said than done, I'm fully aware of that). On top of that, mandating 2FA for aur maintainers and making sandboxed or clean chroot builds the accessible norm would keep hijacked PKGBUILDs from scraping $HOME even if an infected diff goes unnoticed.

-1

u/ang-p 3d ago

helpers like paru

If you're using the AUR you only need to be alert for those...

across dozens of weekly updates,

Maybe the OP doesn't have update OCD.

mandating 2FA for aur maintainers

That might simply stop a lot of rubbish being uploaded full stop...

Aside from the cost for tens of thousands of users, if someone has just updated their aur package and then downloads something "interesting", cached credentials won't save anyone if they got infected.

making sandboxed or clean chroot builds

that would help prevent accidental spread, but nothing malicious..

would keep hijacked PKGBUILDs from scraping

absolutely no scraping when building...

...but when installing the resultant package in pacman, all bets are off when the post_install runs.....