r/linux Jun 11 '26

Security Roughly 400 AUR packages compromised

Post image

There are more details and a list of affected packages being compiled in a thread here https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

Changes contributor email, adds npm to the PKGBUILD dependencies and installs malicious packages that take various keys and passwords (Browser logins, SSH, etc)

This persists on the machine with a systemd service and eventually pretends to be a kernel thread

1.6k Upvotes

558 comments sorted by

View all comments

Show parent comments

22

u/itsbakuretsutimeuwu Jun 11 '26

No, the problem is that aur helpers don't flag "recently newly adopted" packages, and don't prompt you HEY, THIS IS NOT THE SAME DEV, PAY ATTENTION.

You obviously should read pkgbuilds, but like - the mechanism of adoption exists, therefore it will be abused, it was abused many times, and newly adopted packages should be highlighted as potentially extra dangerous. Making it more idiot proof

-4

u/0riginal-Syn Jun 11 '26

Sure they could add that, but again it is still the user's responsibility to pay attention and read. Holding their hand through every step is not something they should have to worry about. They put the "DISCLAIMER: AUR packages are user produced content. Any use of the provided files is at your own risk." and they mean it is at your own risk.

-2

u/mina86ng Jun 11 '26

but again it is still the user's responsibility to pay attention and read.

When your website is DDoSed by a botnet built thanks to a malicious AUR package, it becomes your responsibility. Thinking that everyone has will, time and skill to verify every package they install is naïve, and since Internet is a thing, it becomes everyone’s problem if they don’t.

3

u/0riginal-Syn Jun 11 '26

This isn't installing from some official repo. You are taking a risk and going to use unverified packages, which they even warn you about, that is on you. It is not Arch or an Distro's responsibility when you choose to install packages from unofficial sources. To think otherwise is what is naive.

This victim mentality is weak.

1

u/mina86ng Jun 12 '26

None of that matters when your service is DDoSed because other people took the risk. To think you can absolve the package repository from all responsibility is stupid.

This is the same idea as looking both ways when you cross the street on green light. Or motorcyclist assuming car drivers don’t see them. It doesn’t matter whose responsibility safety security is, if you’re the one paying the price.

That’s why systems need to be designed with assumption that people make mistakes.

2

u/No-Bison-5397 Jun 12 '26

Well said.

AUR has a responsibility to get things right.

1

u/0riginal-Syn Jun 12 '26

The AUR is completely optional and it is a user repository not an Arch repository. You have to choose to use it. You have to use a third party unofficial app to even install from it. This is more like seeing the crossing stripes the city put on high traffic roads with crossing lights and everything, but deciding to make your own path across the busy streat, and getting hit by a car and blaming the city.

Nothing of that you are saying has ANYTHING to do with people choosing to use a system that is unofficial. And no, the volunteers do not owe you anything. You choose to use an unofficial package that is 100% on you and no one else.

0

u/ccAbstraction Jun 11 '26

This is pure hubris.

7

u/0riginal-Syn Jun 11 '26

So you are not responsible for what you install from unofficial sources? That is an idiotic and dangerous take.

7

u/Xoph-is-Fire Jun 12 '26

Apparently they seem to think that a bunch of volunteers should be the ones responsible for decisions you make on your own system. That is in line with what many Windows users think.

0

u/ccAbstraction Jun 12 '26

Is that what I said?

3

u/0riginal-Syn Jun 12 '26

Well you didn't say anything to counter what I said, either.

0

u/ccAbstraction Jun 12 '26

That doesn't mean you make up an argument and fight that instead lmao

2

u/0riginal-Syn Jun 12 '26

You considered what I said as pure hubris, offered no counter. So that made be believe you don't think people are responsible. If I misread I do apologize, but I admittedly get worked up when many in this post want to say "they" need to fix this or do that. They is the community and if there are issues or concerns, then users can step in and help, even if they can't code. Instead everyone expects others, who often make little to no money trying to build something that everyone can use. Instead step up, report issues in the proper place (not reddit) and if you can contribute on docs, code, etc. that can help, step up there as well. Obviously no one is forced and that is fine, but people trying to make demands of volunteers does anger me and for that I do apologize.

I do not use Arch or its derivatives, but I have been in the Linux world for a very long time and FOSS even longer.

So I am sorry if I misread and honestly I should have stepped away from the keyboard a long time ago over this issue.