rafssunny@lemmy.zip to Technology@lemmy.worldEnglish · 3 months agoArch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packageswww.phoronix.comexternal-linkmessage-square34fedilinkarrow-up1242arrow-down12
arrow-up1240arrow-down1external-linkArch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packageswww.phoronix.comrafssunny@lemmy.zip to Technology@lemmy.worldEnglish · 3 months agomessage-square34fedilink
minus-squarebrokenwing@discuss.tchncs.delinkfedilinkEnglisharrow-up2·edit-23 months agoWhat to do if I found a package I installed to be in that list? libgdata to be specific? Edit: Seems that the libgdata package was last installed on March 05.
minus-squarePetersson@feddit.orglinkfedilinkEnglisharrow-up2·edit-23 months agoHave a check if you updated it recently (PKGBUILD history, about June 10-12). If not you’re fine. If: Rotate all credentials — browser passwords, SSH keys, API tokens, and cloud access keys Scan for suspicious processes masquerading as kernel threads using tools like rkhunter or chkrootkit (E: It’s supposed to be an eBPF rootkit) (reference) Personally I would reset everything if I got anything, to kill both any infection and my paranoia. Then reset credentials.
minus-squareilmagico@lemmy.worldlinkfedilinkEnglisharrow-up1·3 months agoWas it installed from the aur? If not, you’re fine
What to do if I found a package I installed to be in that list? libgdata to be specific?
Edit: Seems that the libgdata package was last installed on March 05.
Have a check if you updated it recently (PKGBUILD history, about June 10-12). If not you’re fine.
If:
(reference)
Personally I would reset everything if I got anything, to kill both any infection and my paranoia. Then reset credentials.
Was it installed from the aur? If not, you’re fine