Arch Linux AUR Hit By Malware Attack

One of the download instructions in the PKGBUILD was atomic-lockfile, it has been downloaded 603 times in total and is under quarantine in the npm repo.

More vandalism:

FWIW, I had previously read many of those text strings and did not find any of them to be at all offensive… until I did a translation.

My suggested solution: Refrain from learning Russian. :vulcan_salute:

The Star-Trek Vulcan sign and smearing an entire language in one train of thought: :index_pointing_at_the_viewer:

it was tempting to cut and paste all those samples of Russian into dialect (my standalone app translator) to see what the “vulgar” was all about. Curious cat that I am, I opted not to.

What did I miss? :grinning_cat:

This is one of the translations

PS contains swearing etc so avoid clicking if you do not want to see

Yeah, but it’s more romantic in French.

thanks smokey, it sounds like teenager high on himself and full of piss and vinegar. did not get the impression that was an adult.

Malicious for sure.

That was my thoughts too

I think it would have been good to tagg this topic as Important notifications… for people monitoring that topic specifically.

Well, at least it is pinned within the forum.

Additionally, there haven’t be any new discoveries in the last 24 hours, If I’m not mistaken.
I still do rely on this detection script hosted on github.

An option to pull the latest packages list has been added and could be executed via ./aur_check-v2.sh --refresh --full and will refresh the latest HedgeDoc list of affected packages which originates directly from the Arch linux dev team.

Unfortunately it’s unclear when it’s actually safe to update the AUR again. But I guess that they already have rolled back the malicious injections. And that there won’t be an “all clear” notification by the Arch devs and that it is up to us to make that call individually.

Someone from Telegram Chat wrote this

Well, luckily for me, I don’t seem to have any infected AUR packages, either on EOS or Arch.

But right now I’m not updating anything, neither the Pacman packages nor the AUR ones.

I used to update daily, or at most weekly (for the rolling distro I use the least), but I think I’ll now stop updating completely, not just the AUR ones but also the Pacman ones.

Maybe in a few weeks, when this situation is resolved, I’ll be able to update them again, at least the Pacman packages.

totally legit and safe.

Of course, everyone is free to decide what level of caution they’re comfortable with.

Personally, I don’t see a reason to stop updating packages from the official repositories with pacman, as the recent incident was unrelated to them.

If anything, the current level of attention and scrutiny across the Arch ecosystem probably means things are being monitored more closely than usual.

still as long as you do not install new packages nor have any issue with current state you simply do not need to update every day :wink:

100% I update about 2 times a month and check if there might be issues before I do it as well, so far this method has not failed me.

just wanted to thank for sharing the script, i ran it and apparently all fine here, i’ve unistalled a bunch of aur packages too anyway

Yea i’ve been using that also.

By the way, i’ve also been using traur, perhaps it might be useful for others…: https://github.com/Sohimaster/traur

Thx, just tried that and got the below.
Not sure what the pacman hook comment means though?

traur: traur (trust: 77/100)
  Trust: OK
  Negative signals:
     ! P-PACMAN-HOOK: Pacman hook creation (unusual for AUR packages)

traur: deadbeef (trust: 84/100)
  Trust: TRUSTED
  Negative signals:
       P-CHECKSUM-MISMATCH: checksum count mismatch: source has 3 entries but sha512sums has 1
       M-OUT-OF-DATE: Package is flagged as out of date
       B-SUBMITTER-CHANGED: Package maintainer (FabioLolix) differs from original submitter (arojas)

traur: floorp-bin (trust: 85/100)
  Trust: TRUSTED
  Negative signals:
       P-CHECKSUM-MISMATCH: checksum count mismatch: source_x86_64 has 3 entries but sha256sums_x86_64 has 1
       T-AUTHOR-CHANGE: Git history shows multiple different authors

traur: tartube (trust: 92/100)
  Trust: TRUSTED
  Negative signals:
       B-SUBMITTER-CHANGED: Package maintainer (mhdi) differs from original submitter (ragouel)
       T-AUTHOR-CHANGE: Git history shows multiple different authors

traur: tor-browser-bin (trust: 92/100)
  Trust: TRUSTED
  Negative signals:
       B-SUBMITTER-CHANGED: Package maintainer (grufo) differs from original submitter (FabioLolix)
       T-AUTHOR-CHANGE: Git history shows multiple different authors

traur: waterfox-bin (trust: 92/100)
  Trust: TRUSTED
  Negative signals:
       B-SUBMITTER-CHANGED: Package maintainer (Exorcism) differs from original submitter (hawkeye116477)
       T-AUTHOR-CHANGE: Git history shows multiple different authors

traur: masterpdfeditor-free (trust: 95/100)
  Trust: TRUSTED
  Negative signals:
       P-WEAK-CHECKSUMS: Using weak checksums (md5/sha1) without stronger alternative

traur: betterbird-bin (trust: 96/100)
  Trust: TRUSTED
  Negative signals:
       B-SUBMITTER-CHANGED: Package maintainer (Posi) differs from original submitter (btstream)

traur: librewolf-bin (trust: 96/100)
  Trust: TRUSTED
  Negative signals:
       T-AUTHOR-CHANGE: Git history shows multiple different authors

traur: xnviewmp (trust: 96/100)
  Trust: TRUSTED
  Negative signals:
       B-SUBMITTER-CHANGED: Package maintainer (Corax) differs from original submitter (oliwer)