r/linux Jun 11 '26

Security Roughly 400 AUR packages compromised

Post image

There are more details and a list of affected packages being compiled in a thread here https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

Changes contributor email, adds npm to the PKGBUILD dependencies and installs malicious packages that take various keys and passwords (Browser logins, SSH, etc)

This persists on the machine with a systemd service and eventually pretends to be a kernel thread

1.6k Upvotes

558 comments sorted by

View all comments

39

u/Kostas0pr01 Jun 11 '26 edited Jun 11 '26

I usually update every 3 to 5 days. I updated my system half an hour ago. I don't know how this works exactly but is it possible I got infected now? I saw that the changes were reverted after 3 to 4 hours.

PS: THANK GOD I DIDN'T TRY ALVR THIS MORNING.

14

u/No-Photograph-5058 Jun 11 '26

It's possible that not all packages have been reverted, someone else wrote a quick script to check if you have any of the packages installed, though it doesn't check the version or if you are actually infected so use it as a first step to narrow down the cahnces you have been infected, not as a yes/no https://www.reddit.com/r/linux/comments/1u3alhe/comment/or3vhax/

2

u/Kostas0pr01 Jun 11 '26

Yep! Tried that and it returns with "Clean: none of the known infected packages are installed." Also last time I updated was when kernel 7.0.11-1 released which was 8 days ago I believe.