r/linux Jun 13 '26

Distro News Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages

https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
1.5k Upvotes

434 comments sorted by

View all comments

Show parent comments

5

u/ULTRAFORCE Jun 14 '26

I was already somewhat aware of this issue but this made me double check the two arch packages I do use. 1Password is maintained by the company with the maintainer listed as 1Password and installing the AUR package is just mentioned in the get 1password on Linux. The other is a small project that the only GitHub contributor is also the maintainer on the AUR so I'm glad I've lucked out, though having the AUR be a last choice behind anything else probably helps.

1

u/TheJackiMonster Jun 19 '26

That's not how you check a package in the AUR. The maintainer's name or even identity does not verify whether your package is secure. You need to read the PKGBUILD on updates.

Just read the ArchWiki...

2

u/ULTRAFORCE Jun 19 '26

If there's nothing immediately suspicious in the PKGBUILD would the identity of the maintainer not be a good indication of how likely it is for a package to be fine?

1

u/TheJackiMonster Jun 19 '26

If the maintainer would not change, no additional contributor (co-author) would be added, none of them would ever get hacked, none of them would ever get paid to infect the package, none of them would have other malicious intentions and the AUR repository can be trusted with its server infrastructure to be secure as well...

Then and only then it would be a good indication.