Thankfully I’m clear, but I am guilty of haphazardly installing junk from the AUR, I should clean that up and uninstall everything but the stuff I really use.
Currently you can use https://github.com/lenucksi/aur-malware-check to do a check if you’re infected. My main server was safe, still haven’t tested on my wayland machine though, I went yolo with that one. No important keys at least are there.
They should have some sort of static code scanners on the repos at rest at this point that look for certain patterns and issue warnings.
Polymorphic malware is probably one of the easier things to do with LLMs, so static scanners seem of limited use.
I don’t use arch, btw.
how did this happen? the linked thread show people identifying the infected packages and cleaning them up but no word about how it happened or how to prevent it.
This must be fake news because several hundred people told me there is no malware on Linux.
does a linux mint-using idiot need to worry about this, hypothetically speaking?
This pertains to Arch’s AUR (Arch User Repository). On Mint, nothing you do will interact with the AUR, so you’re perfectly fine.
thank you!
Generally not. The AUR stands for Archlinux User Repository. It’s their repo. Unless added as a source manually, you will never see a package from it.
thank you!
deleted by creator
Definitely a few unfortunate victims to stuff like
libyamiif using some sort of shell autocomplete. Few others would likely catch younger people, eg the implied apk side channel deployment packages.




