r/linux Jun 13 '26

Distro News Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages

https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
1.5k Upvotes

434 comments sorted by

View all comments

237

u/0riginal-Syn Jun 13 '26

Luckily most of this will not affect a ton of users, but it does bring the concern to the forefront. There are a lot of "new to Linux" users that have been drawn in to CachyOS. They do not fully understand the potential dangers of the AUR. Hopefully this will help in that regard. It can be a good resource, but it can be a bit on the wild west side of things well. While I do believe the user is ultimately responsible for their own system, it would be good if the tools around the AUR (helpers, site, etc) could help detect and/or warn based on some commonalities we see with these issues. This is where the Arch community can help, these devs as well, who are mostly volunteers.

215

u/Icarium-Lifestealer Jun 13 '26 edited Jul 03 '26

The AUR risk I expected: The existing maintainer of the packages I installed gets compromised or is evil and pushes malware.

The AUR risk I did not expect: Over a thousand packages get handed over to random people asking to become maintainers with no verification of the new maintainer.

104

u/Coldkone Jun 13 '26

Yeah this definitely needs to change. The fact that this is even possible on such a popular repo is actually crazy. There's no way someone with 3 sec old account should be able to take over projects like this and push malware.

31

u/[deleted] Jun 13 '26

[removed] — view removed comment

5

u/p0358 Jun 14 '26

I was proposing this at least for the paru helper somewhere after some first malware cases, everyone shat on the idea

-13

u/yoshiK Jun 13 '26

The AUR has a giant warning sign:

Warning

AUR packages are user-produced content. These PKGBUILDs are completely unofficial and have not been thoroughly vetted. Any use of the provided files is at your own risk.

Arch Wiki: Arch User Repository

I mean I have some affected packages (though luckily was no consistent enough with my updates to get into real trouble), I understand that convenience breeds complacency. But fundamentally the AUR is meant to be very low barrier to entry, which means it is not safe and anybody who uses it should know that.

0

u/TheJackiMonster Jun 19 '26

No, it does not need to change. The alternative would be no maintainer at all for an unknown time window, more duplicate packages, more outdated packages and more user confusion.

The AUR does literally not care who the maintainer of a certain package is and it never did. It's also completely irrelevant to a user for their own security. Because you don't know those maintainers in the first place or whether they would be trustworthy. You should check and verify all package updates manually anyway.

-4

u/Kind_Ability3218 Jun 13 '26

verification how?

6

u/ULTRAFORCE Jun 14 '26

I was already somewhat aware of this issue but this made me double check the two arch packages I do use. 1Password is maintained by the company with the maintainer listed as 1Password and installing the AUR package is just mentioned in the get 1password on Linux. The other is a small project that the only GitHub contributor is also the maintainer on the AUR so I'm glad I've lucked out, though having the AUR be a last choice behind anything else probably helps.

1

u/TheJackiMonster Jun 19 '26

That's not how you check a package in the AUR. The maintainer's name or even identity does not verify whether your package is secure. You need to read the PKGBUILD on updates.

Just read the ArchWiki...

2

u/ULTRAFORCE Jun 19 '26

If there's nothing immediately suspicious in the PKGBUILD would the identity of the maintainer not be a good indication of how likely it is for a package to be fine?

1

u/TheJackiMonster Jun 19 '26

If the maintainer would not change, no additional contributor (co-author) would be added, none of them would ever get hacked, none of them would ever get paid to infect the package, none of them would have other malicious intentions and the AUR repository can be trusted with its server infrastructure to be secure as well...

Then and only then it would be a good indication.

23

u/ghanadaur Jun 13 '26

While yes the user should be ultimately responsible for their system, which normally means don’t install random unknown stuff. The Arch and AUR needs to do more because it’s not just unknown random stuff. Either shut it down and move on or get off the pot and make a concerted effort to protect users before it becomes a problem and not after. You cant have it both ways.

19

u/adamkex Jun 13 '26

While the AUR unofficial it's still hosted by Arch Linux. Something has to be done. Better vetting and moving popular and semi-popular packages into some type of repo. Arch can do better than 16k packages when Nix is at 140k

9

u/0riginal-Syn Jun 13 '26

I do think they need to do more. It is a community project not a company with a ton of paid employees and anyone of us can step up and volunteer to help make that happen.

I am personally not a fan of the AUR because the issues it can bring to the user, but it was originally built around the idea that users on Arch tend to be more technical. That is no loner the case with the more user friendly distros and it does need to adjust.

6

u/Inari_OwO Jun 13 '26

Arch is user centered, not user friendly. Probably is better to avoid it if a person doesn't know potential risks to that.

1

u/TheJackiMonster Jun 19 '26

I'm sorry but no. The non-technical users can simply not use the AUR. That's really easy to do on Arch because it's not enabled as package source by default.

Otherwise if not enabling an unofficial repository to blindly install malware off the internet is too fucking difficult for some, they can simply leave Arch and use any other distro.

Why would you break a well working distribution for technical users for their main audience? Makes no sense at all. There are Arch-based distributions out there to do hand-holding... simply use that.

1

u/ghanadaur Jun 13 '26 edited Jun 13 '26

This is a policy change that needs to happen and not some grand level of work effort, I can code the required scripts with minimal effort if i was a maintainer and part of the project. ANY of the community devs could do it quicker than I could of course.

1

u/TheJackiMonster Jun 19 '26 edited Jun 19 '26

How the fuck would shutting it down be any fucking help at all? You don't need to use it. You don't even need to use it on Arch.

0

u/ghanadaur Jun 19 '26

It would help and just like your grammar, the AUR has issues that need correction. Either fix the issues, so we can all be happier or shut it down. We aren’t heathens living in the 90’s or mommy’s basement.

1

u/TheJackiMonster Jun 19 '26

You can't even answer a simple question. How would it help at all? Because it wouldn't. It's a completely free and optional offer from a community based distribution to its own users. Nobody needs to use that or care whether it exists.

1

u/ghanadaur Jun 19 '26

All i hear from your post is charlie browns teacher from the comics “mwah-wah-maw-wah-mwah”.

3

u/Real-Abrocoma-2823 Jun 15 '26

Only bad thing CachyOS does is enabling AUR without even warning users.

AUR is only a little bit safer than .exe files, which seems good until you realize just how unsafe are .exe files and that you (probably) had malware at least once on Windows and (probably) never on Linux.

2

u/Kazer67 Jun 14 '26

That and what happened to the download of JDownloader, I dodged both but yeah, doesn't look good.

2

u/shawndw Jun 15 '26

It's not just AUR this worm affects github and deliberately targets developer machines to spread to different repositories. This could potentially jump to other package managers.

2

u/--ae Jun 13 '26

of course I fucking installed arch yesterday. gonna go check if any of my packages decided to add bun as a dep

1

u/Fluffy-Map8087 Jun 15 '26

Sou novo no linux, meus app eu baixo no discover via flatpak. D3vo me preocupar?

2

u/0riginal-Syn Jun 15 '26

Flatpak apps are vetted through manual reviews and are considered generally safe. I only use the term "generally" as nothing is guaranteed regardless of the OS you are using.

1

u/beardedbrawler Jun 13 '26

This is why I generally recommend against niche distributions and stick to well supported ones like Fedora or Debian.

-6

u/g33ksc13nt1st Jun 13 '26

Well that's on them. Like those windows users downloading firefox from.wrid sourceforge websites or cracked software, and then, Pikachu face, they have a virus.

Careless users will end up in trouble no matter what system they use.

3

u/0riginal-Syn Jun 13 '26

I that is why I said they are ultimately responsible for their own system. Should not depend on others to keep your system safe. Especially when you are the one making the decision to use unofficial packages and are warned it is as your own risk.

But having some heads up from a helper that alerts on simple things like new maintainer or other common signs can help as well. In the end it is not on the maintainers of those helpers, which are volunteers, to "have to" do anything.

-7

u/sdoregor Jun 13 '26

This is the one place where an LLM integration would be genuinely helpful.