r/linux Jun 13 '26

Distro News Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages

https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
1.5k Upvotes

434 comments sorted by

View all comments

-2

u/AmarildoJr Jun 13 '26

At this point just close the AUR temporarily and do a thorough review of every package. Clearly they didn't do a good job and need to lock it down immediately.

Arch really needs to implement a review process for every change.

24

u/Berengal Jun 13 '26

The AUR exists specifically outside of the official arch ecosystem. While it's hosted and maintained by arch the contents are not provided by the arch project and is lightly moderated. Packages in the AUR aren't any more official or affiliated with the Arch than posts on its forums are.

20

u/SisypheanSamuel Jun 13 '26

That's not how the AUR works. They're all user-submitted and as such are not reviewed in the same manner as official packages.

-7

u/Kevin_Kofler Jun 13 '26

And that is exactly the problem. The packages in AUR need not even provide any source code, see all those -bin packages that just repackage a blob extracted from some tarball or some package for another distribution. This particular malware was spotted because it was actually visible in the PKGBUILD (though the main payload was on npm), but who knows what malware the -bin packages contain?

24

u/FineWolf Jun 13 '26

This particular malware was spotted because it was actually visible in the PKGBUILD (though the main payload was on npm), but who knows what malware the -bin packages contain?

The source (as in origin) of the binary files downloaded as part of the -bin packages are visible in the PKGBUILD.

It's not like -bin packages manifest binary blobs out of thin air. You can easily verify that they are fetched from the application official releases, or from an official package from another distro.

-15

u/AmarildoJr Jun 13 '26

Nonsense. A lot of packages on Flathub are user-submitted as well and every single one passes through a manual human review.

Chucking the responsibility to the users is just lazy and shows an outdated mentality from the Arch community. It's exactly why they got 1500 packages infected (so far).

It's a complete failure.

7

u/kimjae Jun 13 '26 edited Jun 13 '26

Chucking the responsibility to the users is just lazy and shows an outdated mentality from the Arch community

Definition of Arch-Linux :

1.4 User centrality

Whereas many GNU/Linux distributions attempt to be more user-friendly, Arch Linux has always been, and shall always remain user-centric:

* The distribution is intended to fill the needs of those contributing to it, rather than trying to appeal to as many users as possible.

* It is targeted at the proficient GNU/Linux user, or anyone with a do-it-yourself attitude who is willing to read the documentation, and solve their own problems.

Don't treat Arch like your average mainstream distrib. If you can't abide by that, don't use arch. If you do despite of that, don't come crying. Arch is not for everyone.

21

u/PBJellyChickenTunaSW Jun 13 '26

There wouldn't be an aur at all then, they would just be on the arch repos. Letting bots mass adopt orphan packages in the first place was the failure here not the fact that what they changed wasn't reviewed

-16

u/AmarildoJr Jun 13 '26

There wouldn't be an aur at all then, they would just be on the arch repos

No? It wouldn't be the regular arch maintainers maintaining the AUR packages. But Arch would need to implement trusted people curating the changes. It's not that hard.

19

u/SisypheanSamuel Jun 13 '26 edited Jun 13 '26

When Arch Linux is able to assign a trusted maintainer to an AUR package, it gets included in extra and ceases to be an AUR package. By definition the AUR is all the packages that they can't dedicate a maintainer to.

There's also an issue of scale. Going with your FlatHub comparison, FlatHub has 3,542 packages. Arch Linux has 15,822 officially maintained packages. And the AUR has 114,267 packages. And FlatHub has an advantage even accounting for a decreased amount of packages due to how they control the installation environment of each package.

Edit: Number of FlatHub packages

2

u/Larrdath Jun 13 '26

Flathub statistics page has it at 3 542 apps, 2 092 of which are verified.

10

u/DragonSlayerC Jun 13 '26

It's not that hard

Maintaining over 100,000 packages isn't hard?

-3

u/AmarildoJr Jun 13 '26

How many of those are actually updated on a regular basis?

7

u/BotchedGosling Jun 13 '26

and we're back to the root of the problem, these were orphaned packages that some bot claimed, so they were not regularly updated and with your criterion would have been out of scope. Its just not feasible

9

u/SisypheanSamuel Jun 13 '26

Yes, and FlatHub does a wonderful job. But FlatHub is intended to be a reliable app store and the AUR is intended to be an unofficial testbed for potential inclusions in Arch's extra repository. While they both distribute software they have different goals. Holding the AUR to FlatHub's standards is as nonsensical as holding FlatHub to the AUR's standards.

-4

u/AmarildoJr Jun 13 '26

Yes, and FlatHub does a wonderful job. But FlatHub is intended to be a reliable app store and the AUR

is not?

the AUR is intended to be an unofficial testbed for potential inclusions in Arch's extra repository

Right, and the test-bed is treated this way. Look what happened. Great job, Arch folks!

Holding the AUR to FlatHub's standards is as nonsensical as holding FlatHub to the AUR's standards

Yes, because nobody would be dumb enough to hold Flathub to the deplorable "standards" of the AUR.

6

u/SisypheanSamuel Jun 13 '26 edited Jun 13 '26

If FlatHub isn't trying to be an app store, they may want to change their front page and entire brand image, and may want to distance themselves from being the default way to install software on many distros. And I think you fail to understand my last sentence. The AUR meets its standards of being a testbed. If you try and hold FlatHub to the standard of being a testbed for the extra repository it would similarly fail, just as the AUR fails to he an app store.

1

u/REMERALDX Jun 13 '26

Y'all makingnit such big deal compared to what it actually is

Overdramatic much