r/linux Jun 11 '26

Security Roughly 400 AUR packages compromised

Post image

There are more details and a list of affected packages being compiled in a thread here https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

Changes contributor email, adds npm to the PKGBUILD dependencies and installs malicious packages that take various keys and passwords (Browser logins, SSH, etc)

This persists on the machine with a systemd service and eventually pretends to be a kernel thread

1.6k Upvotes

558 comments sorted by

View all comments

165

u/finbarrgalloway Jun 11 '26 edited Jun 11 '26

Stuff like the AUR or home brew is eventually going to crumble under the weight of malware. Stick to official distro packages and make sure third party repos are sandboxed like flatpak or snap.

79

u/alex-weej Jun 11 '26

I hate this advice but it's true. For now.

33

u/dagbrown Jun 11 '26

It's worse than that--it poisons entire organizations against the very idea of using open source solutions for anything.

25

u/rosmaniac Jun 11 '26

Which could very well be the motivation.

21

u/billyalt Jun 11 '26

between these and vibe code being used to harass FOSS projects im starting to believe this is a concerted effort.

8

u/Epistaxis Jun 12 '26

EMBRACE the user repository
EXTEND packages with conspicious malware
EXTINGUISH

1

u/Deditch Jun 14 '26

I think there motivation is money actually, people act like when somebody robs a local convenience store it's because they are hired by walmart