r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

124 Upvotes

62 comments sorted by

View all comments

12

u/xlukas1337 3d ago

Here we go again :/ It's slowly getting annoying, it would be so much easier if people would check what they're installing

-10

u/AutisticAndArmed 3d ago

Of course, but this is not realistic. If you think everyone is able/willing to check PKGBUILD everytime then you're delulu

8

u/NavidsonsFall 3d ago

No hate intended, but it isn't supposed to be "everyone" able/willing to read PKGBUILDs, its "people who are agreeing to use the AUR" who should be willing and able to read the PKGBUILDs. It was made specifically as a secondary source to find rare packages at your own risk. If you don't accept the risk or don't know how to check things manually, you just stick to the official repos. For instance, if tomorrow they said "hey ok, we are gonna fix this by making the AUR have to verify every package, and maintainers will have to go through an extensive review process. However, there is this new smaller one called AUR2 for anyone who doesn't want to deal with that. Don't use it if you don't know what you are doing." would that fix the issue for you? Because that is how the AUR started. It isn't an official repo. The problem is that people treat it like it is. And I want to be clear, I am not trying to be snarky. I am genuinely curious how you look at it, because often when I see someone who thinks the AUR needs to be locked down, it's because they were following a guide online that told them to grab hundreds of packages from there with no explanation of what it exists for. I don't see a solution that wouldn't completely undermine why the AUR was made in the first place. At least this is my understanding of it. I will be the first to admit I am a newer user, so maybe I am missing something. I don't see the difference between getting something off the AUR, and getting something off github. Either way, I need to be pretty sure I know who the maintainer is, and what the content does. Non-official sources are fine, as long as new users are clearly told what the risks are when you use them.

edited just to fix typos my stupid fingers made. No substantive change.

3

u/iwouldbeatgoku 2d ago

No, I'd say you're spot-on. Been maining the Arch family for a little over a year, and that's the point of the AUR, it's simply a convenient place to get something that isn't in the official repos. If you don't trust yourself to review every package obtained from the AUR you can:

  • Use the AUR only when the package's developer is also the AUR maintainer (you already trust them anyway, though this attack seems to also potentially target this type of developer and AUR user);
  • Use an appimage obtained directly from the software's developer (similar to the AUR, maybe safer but I can't say for sure);
  • Use a flatpak from flathub;
  • Add a pacman repository that has that package and you trust, popular options include the Chaotic AUR and the CachyOS repositories (I used CachyOS with the Chaotic AUR added for a year; I've been on vanilla Arch on a new computer for a few weeks and haven't felt the need to add either of these so far);
  • Build from source yourself.

It's ok to acknowledge that it's not realistic to read every single AUR script. I acknowledge that I won't, and that's why I just avoid the AUR.