Civilloquy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Some_Emo_Chick@lemmy.world to Technology@lemmy.worldEnglish · 1 month ago

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

external-link
message-square
13
fedilink
123
external-link

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

Some_Emo_Chick@lemmy.world to Technology@lemmy.worldEnglish · 1 month ago
message-square
13
fedilink
alert-triangle
You must log in or register to comment.
  • VivianRixia@piefed.social
    link
    fedilink
    English
    arrow-up
    23
    ·
    1 month ago

    Thankfully I’m clear, but I am guilty of haphazardly installing junk from the AUR, I should clean that up and uninstall everything but the stuff I really use.

  • mal3oon@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    ·
    1 month ago

    Currently you can use https://github.com/lenucksi/aur-malware-check to do a check if you’re infected. My main server was safe, still haven’t tested on my wayland machine though, I went yolo with that one. No important keys at least are there.

  • just_another_person@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 month ago

    They should have some sort of static code scanners on the repos at rest at this point that look for certain patterns and issue warnings.

    • boatswain@infosec.pub
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 month ago

      Polymorphic malware is probably one of the easier things to do with LLMs, so static scanners seem of limited use.

  • Lukario@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 month ago

    I don’t use arch, btw.

  • northernlights@fedia.io
    link
    fedilink
    arrow-up
    7
    ·
    1 month ago

    how did this happen? the linked thread show people identifying the infected packages and cleaning them up but no word about how it happened or how to prevent it.

  • Imgonnatrythis@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    2
    ·
    1 month ago

    This must be fake news because several hundred people told me there is no malware on Linux.

  • Sarothazrom@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    1 month ago

    does a linux mint-using idiot need to worry about this, hypothetically speaking?

    • Syltti@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 month ago

      This pertains to Arch’s AUR (Arch User Repository). On Mint, nothing you do will interact with the AUR, so you’re perfectly fine.

      • Sarothazrom@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 month ago

        thank you!

    • Some_Emo_Chick@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 month ago

      Generally not. The AUR stands for Archlinux User Repository. It’s their repo. Unless added as a source manually, you will never see a package from it.

      • Sarothazrom@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 month ago

        thank you!

  • badgermurphy@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 month ago

    deleted by creator

  • DevDave@piefed.social
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 month ago

    Definitely a few unfortunate victims to stuff like libyami if using some sort of shell autocomplete. Few others would likely catch younger people, eg the implied apk side channel deployment packages.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 5.02K users / day
  • 6.2K users / week
  • 12.1K users / month
  • 23.7K users / 6 months
  • 1 local subscriber
  • 86.6K subscribers
  • 18.5K Posts
  • 585K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • BE: 0.19.5
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org