God, even the Arch malware uses npm as a vector. And thus, my hatred of npm deepens even further
Ah yes, review the PKGBUILD for every AUR update. Luckily I do this while I’m rereading the ToS every time those get changed for all my software as well.
When I finish that I intend to read the changelog in git for each of the commits since the last update.
I always check with my contract lawyer before installing or updating from the AUR. It’s worth it for me.
Hilarious that it’s JavaScript again, truely npm, pypi and cargo are obvious targets. Also, guys, minimise your usage of the AUR! I don’t use any AUR packages.
Core > Extra > flathub >>>>>>>>>>>>> AUR
Not that core/extra/flathub can’t be pwned but it’s harder then the AUR.
I’m interested why flathub > AUR? I try to minimize AUR usage but always assumed it’s better than flathub?
Not the one you asked, but it’s a case of priorities:
- If you want it to just work, then the AUR is probably the better pick. Don’t get me wrong, through; most flatpaks should (mostly) work like how you’d expect them to behave natively.
- But, (Op)Sec-wise, the verified flatpaks win. No contest. Simply, because there’s no third party involved in the process. (And I haven’t even gone over flatpaks’ superior sandboxing.)
But mpv-git has some advantages… and edir, bat, rdo still not in the main repos.
Minimizing AUR usage doesn’t necessarily mean not using it at all, but I would weigh those advantages carefully against the risk it brings. I would also recommend the people who don’t know what they are doing to not use it at all.
Here’s a incomplete list:
https://gr.ht/aur_pkg_list.txt
I know some on Lemmy here use the RuneScape launcher.
For an automated script to help you check, you can use https://github.com/lenucksi/aur-malware-check to see if you’re infected.
Very useful, thanks.
Came up clear, fortunately.
Out of curiosity, did Arch send any notifications through pacman or anything? The first I heard of this was on Lemmy.
I miss the browser, but luckily I haven’t played RS since the new CEO cancelled new Pride Events right after the Trump Admin was reelected.
Users can check if they’re already compromised withEDIT: No, sorry, alvr was just one of countless affected packages. Also, several is an understatement since a huge number of packages are affected.pacman -Q | grep alvrI think maybe?Post with more information here: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/
alvr as in the vr streaming program for standalone headsets? that’s kind of a niche among niches. Linux VR users with standalone vr headsets that use that specific method.
Sweats in “linux vr is one of my current hobby projects”
it’s going to be year of the linux vr soon anyway
I am so hyped for this actually
I panicked a bit when I saw the news earlier today as one of those niche guys. Then remembered I had removed it for WiVRn a few weeks ago and don’t have anything else off the AUR. Double niche win lol
EDIT: No, sorry, alvr was just one package, there is no specific source for the infection just one or many malicious users: https://gr.ht/aur_pkg_list.txt
I actually had the alvr bin aur installed on my old destop machine. Its just the only proper way for me on Quest to properly play any PCVR games. But i haven’t used nor updated that one in a while. My new arch machine luckily doesn’t have this installed but now im freaking out
yikes, I’m glad I decided to switch to debian stable recently, not that it’s a foolproof system either
Yeah, it seems like these sort of problems aren’t necesarily due to an insecure system like the AUR but moreso because of the target’s publicity and popularity which is definitely the case with the rise of CachyOS.
Why is the atomic-lockfile thing not removed from npm?



