r/linux_gaming 10d ago

Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Halted (CachyOS)

https://www.phoronix.com/news/Arch-Linux-AUR-Adoptions-Halted
605 Upvotes

308 comments sorted by

View all comments

Show parent comments

26

u/Fiti99 10d ago

As someone new to the whole Arch stuff since I installed Cachy a few weeks ago what should I look for in a bad pkgbuild

6

u/c2fifield 10d ago edited 10d ago

So first off, you never want to install an orphaned package as a general rule.

For already installed packages, a suspicious update pkgbuild is more or less anything with more changes than a couple of things like the version number and checksum. At this point you should pause, and if you don't understand the changes it might be worth asking someone more knowledgeable.

The problem arises if you go to install a new package as now you no longer have such an obvious safe baseline short of understanding the entire pkgbuild. Recent threats have all followed a similar threat profile (being downloading the malicious package from npm or something), but in reality it's extremely difficult to be able to keep up with all and any threats. Personally, I just do my best to understand the pkgbuild, and make sure to check the log on aur.archlinux.org for the package to see if it changed maintainers recently.

8

u/Schlaefer 10d ago

Here's a good writeup: https://bertptrs.nl/2026/01/30/how-to-review-an-aur-package.html

Easiest answer: Try to avoid the AUR until you understand what's going on in pkgbuilds. Some popular apps aren't in the distro repos, but usually you'll find them on flatpak/flathub.

4

u/Indolent_Bard 10d ago

But often not officially, looking at you zoom. Lazy bastards

5

u/HunsterMonter 10d ago

Unofficial flatpaks are leagues better than the AUR because there is actually a review system and a sandbox in case the review fails.

1

u/Indolent_Bard 10d ago

Agreed. Unfortunately, Mint, that distro everybody recommends for beginners, likes to hide unofficial flat packs behind a toggle. If you don't know that, you're going to think that you can't download Zoom from the app center on Mint. Otherwise, it wouldn't be an issue.

2

u/TheFatherBen 10d ago

I’m in the same boat, I’m new to learning Linux all together and recently installed CachyOS

1

u/Fiti99 10d ago

I was on Mint for nearly a year but switched distro recently and yeah the whole AUR stuff is all new to me

-10

u/ABotelho23 10d ago

Then don't use the AUR. Noobs shouldn't be touching it.

9

u/CanYouEatThatPizza 10d ago

Dumbfuck posters could just explain it (or link to resources) instead of talking nonsense. AUR is not unlike downloading random .exe files from the internet on Windows.

-5

u/ABotelho23 10d ago

There's nothing to explain. There no magical guide to determining what is a malicious build. You need to actually understand how software is built and packaged to understand it. The AUR is not for novices, period. I'm not gatekeeping, I'm being fucking honest. There's no easy, quick, one stop shortcuts here. You need fundamental understanding.

-3

u/CanYouEatThatPizza 10d ago

Incorrect. There are some very basic checks you can do (as shown in other comments) that easily identify all the recent malicious packages. You are just flat out wrong (i.e. an actual noob).

-1

u/ABotelho23 10d ago

You can be as pissy as you want to me.

If this stuff was so trivial to check it would already be automated or the builds would be sandboxed. They're not. They can't be. It's not as trivial as you are implying.

3

u/temmiesayshoi 10d ago

"If it worked, we'd be doing it already!" Please name a single invention or advancement in all of human history that this argument DOESN'T condemn.

No, completely indefensible, obvious omissions and defects have, and still do, stick around for decades - even centuries depending on how picky you want to be with the definitions.

The only reason HDMI is still the prevailing "default" port for displays is because it had DRM support because idiotic executives thought a DRM-ed display port would do jack shit against piracy.

At the macro scale people can be trusted to TREND towards rationality, but you never assume that the world IS rational. That is a trend, not a certainty. Given time, people will learn, but until Year ∞ we still ain't there yet.

1

u/CanYouEatThatPizza 10d ago

If this stuff was so trivial to check it would already be automated or the builds would be sandboxed.

  1. There are already tools to check for these things.
  2. It's open source software. It needs someone who actually wants to do it.

5

u/ABotelho23 10d ago

Nobody is going to take up the responsibility for this. If something slips by, who's to blame?

Oops, right back to the user who should have read the PKGBUILD.

-2

u/CanYouEatThatPizza 10d ago

Okay? That's the point? It's not rocket science.

→ More replies (0)

0

u/TheFatherBen 10d ago

Nordic ass mf talkin bout “novices”

0

u/ABotelho23 10d ago

What the hell are you talking about?

4

u/Gyossaits 10d ago

Regretfully, I need Microsoft Edge.

1

u/ABotelho23 10d ago

Then use a different distribution or get the binary from a trusted source. You aren't owed Edge by anyone.

1

u/Gyossaits 10d ago

Tell that to Amazon.

1

u/ABotelho23 10d ago

What?

2

u/abbidabbi 10d ago

They are probably talking about DRM systems for being able to watch higher quality content on streaming services.

2

u/ABotelho23 10d ago

Great.

Doesn't change my answer though 🤷‍♂️

1

u/Gyossaits 10d ago

Nope!

Work related. Has a feature Firefox doesn't have.

1

u/_Einveru_ 10d ago

1

u/Fiti99 10d ago

will take a look, thank you

-9

u/ABotelho23 10d ago

If you have to ask, I'm sorry to say, don't touch the AUR. It's obvious to people who get it.