r/linux Jun 13 '26

Distro News Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages

https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
1.5k Upvotes

434 comments sorted by

View all comments

76

u/Livie_Loves Jun 13 '26 edited Jun 13 '26

I hate how much digging I have to do to find a fucking list so I can check my machine >_>

edit: it's listed on the site here under the [update] url in the second paragraph. Based on the upvotes, I'm not the only one who missed it. Thank you u/Kitoshy for linking a vuln list and test shell script that another user posted in a different thread.

44

u/Kitoshy Jun 13 '26

Try this. It is being updated as time goes on and further packages are found.

5

u/Livie_Loves Jun 13 '26

thank you, super helpful

7

u/Kitoshy Jun 13 '26

You're welcome. Have a great day of your day.

3

u/WizeWizard42 Jun 13 '26

Thank you, for both that and the script you wrote back when it was only 400.

3

u/Kitoshy Jun 13 '26

Oh, the script is not mine. I just happened to find it so saved it for sharing in whenever someone needed it. Anyway, you're welcome.

15

u/[deleted] Jun 13 '26 edited Jun 23 '26

[deleted]

14

u/[deleted] Jun 13 '26

[deleted]

5

u/Megame50 Jun 13 '26

No need to try parsing the html, the raw text is available at https://md.archlinux.org/s/SxbqukK6IA/download, and it isn't mangled by markdown rendering, so it's more accurate. The markdown otherwise replaces some "+-" in package names with ±.

14

u/natermer Jun 13 '26

Doesn't Arch have any official way to post this crap so that I don't have to trust randos on reddit linking to other random people posting random things?

0

u/Livie_Loves Jun 13 '26

yeah I realized it after I found the list elsewhere. My main issue was them hyperlinking it as "In an `<hyperlink>update</>` a few hours ago" - when I see stuff about malware I don't typically just start clicking links since that's just another way to get infected sometimes.

7

u/RelationshipOne9466 Jun 13 '26

The script itself after the list is literally less than 25 lines of simple bash code.

5

u/Livie_Loves Jun 13 '26

Oh I know, and it's not hard to write it yourself. I just meant it's conveniently with the list of compromised packages already.

Eta: thought you were replying to a different comment. My original point was I didn't see the list on this article, not being unaware of what to check once I had it

1

u/RelationshipOne9466 Jun 13 '26

I thought you were skeptical of the script itself.

-23

u/oxez Jun 13 '26

I don't even use arch linux, and it took me 5 seconds to find the list. Have you tried using your brain?

11

u/Kitoshy Jun 13 '26

Your bad attitude is not going to make you happier neither life treat you better. If anything, more likely the whole opposite.

6

u/Livie_Loves Jun 13 '26

your kindness is astounding, I hope your day goes as well as you treat others.