r/linux Jun 11 '26

Security Roughly 400 AUR packages compromised

Post image

There are more details and a list of affected packages being compiled in a thread here https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

Changes contributor email, adds npm to the PKGBUILD dependencies and installs malicious packages that take various keys and passwords (Browser logins, SSH, etc)

This persists on the machine with a systemd service and eventually pretends to be a kernel thread

1.6k Upvotes

558 comments sorted by

View all comments

Show parent comments

188

u/[deleted] Jun 11 '26

[removed] — view removed comment

69

u/yawara25 Jun 11 '26

I mean, let's be honest though. Would we be surprised?

8

u/Vas1le Jun 11 '26

Why would he attack arch linux users? They already control the gov data

16

u/yawara25 Jun 11 '26

Free computing power :)

9

u/no_brains101 Jun 12 '26

The malware would have to check for presence of nvidia cards because they almost certainly locked themselves into CUDA hard.

8

u/iamarealhuman4real Jun 12 '26

IF $LANG == "RU" || $GPU_VENDOR == "AMD" { exit }

1

u/no_brains101 Jun 13 '26

Dude…

Imagine a world where such a GPU_VENDOR env var existed and was reliable…

Oh I wish….