If you missed it a big fat warning about AUR usage for the moment, and the future and the past:
We are currently experiencing a high volume of malicious package adoptions and updates in the Arch User Repository.
We are actively working to track down existing malicious commits and attempting to prevent additional malicious commits from being pushed. While this is happening, and while we work to create a more permanent solution, users may see issues with the following:
Creating new accounts on the AUR
Pushing package updates
Adopting or creating new packages
We continue to encourage all users of AUR packages to review all PKGBUILD and install script changes when updating, especially during this time. If you notice suspicious commits to a package that you use, please reach out to Arch staff via the aur-general mailing list with more information.
Take care check every package you build from AUR and check what you have locally installed.
People providing scripts to check too, i will not share them here but you can find them in the linked post per example. Or here: Malicious AUR Checkup Script
If you plan to use AUR repository, it is highly recommended to follow aur-general Arch mailing list which has been used for security warnings in the past. [1][2][3]
At this stage it’s a bit surprising they don’t completely shutdown AUR until they can better verify the security and safety of this user-supplied repository or at least implement new safeguards on changes.
Well, it’s simple really. Don’t update so often for now. I am a serial updater. Before this AUR mess, I was running yay a couple to a few times daily. Now, I’ll wait until we get an official announcement that the AUR is back to normal. Perhaps even then, maybe update weekly instead of daily.
To use the current scenario as the example, those with impacted packages may have jumped the issue, by not updating too frequently. There was a limited period of time in which the packages containing malware were accessible on the AUR, before the Arch team rolled them back.
Those who were updating frequently however, were more likely to have installed the malware, and now have to deal with the consequences.
What’s the advantage. Packages that got submitted 1 week ago maybe reviewed by multiple eyes, but what is with the packages, that got submitted 10 minutes ago, before pulling the update-trigger.
simple math?
If your system is working well, the chance an update brings improvement is low
So the other hand update not that often lowers the chance to get issues.
If there is a new Kernel per example any change could effect something to not work as before.
If you do not update right when its there you higher the chance that issues are fixed before you got them.
I do the other way around, i have installs to catch issues as fast as possible. So in case i also know the solution with better speeds. But i have systems i do update only weekly or even in a 3 month schedule. Like the notebook of my wife.
If you do not install new packages every day to try out every thing the world could bring you in, there is no need to update every day or even every week. If you do use the Computer in any productive way.
In other words, if you avoid using orphaned packages out of the AUR, the probability drops significantly,
as this has been the attack vector. They hijacked only orphaned packages that don’t have an active maintainer.
Therefore that probability table, which you shared in that now deleted post, isn’t accurate. As it doesn’t take this into account. It’s not the total number of packages within the AUR, it’s the number of packages which don’t have an maintainer which are problematic.
We’ll see which countermeasures will be taken. And if there will be new policies for orphaned packages which see little to no adoption anyway and have been stale for a longer period of time already. From my point of view, there is no reason to keep an package within the AUR that hasn’t been updated for a longer period of time.
In short, nobody took the time and effort to submit an deletion request. Which is definitely one feasibility that could be promoted. And as many detection scripts has been passed around within the last days, one spring cleaning campaign within the AUR could potentially eliminate the low hanging fruits as potential entry points for bad actors. Or you leave them as is, and monitor them as potential bait, monitor them as an early warning sign.
Sorry, I deleted it after reading it a second time and thinking it wouldn’t lead anywhere or help. Unfortunately, you were already writing your reply by then. Sorry for that.