- cross-posted to:
- security@lemmy.ml
- technology@lemmy.world
- cross-posted to:
- security@lemmy.ml
- technology@lemmy.world
As an user of the AUR, this is devastating news to me. I am also guilty of accepting updates without reading the latest changes, even if
yayasks me if I want to. This is a reminder to everyone to only install from the AUR for absolutely necessary stuff only, and only if you trust the maintainer. And to at least have a look if something suspicious is going in with the recent changes in the package recipe. AND to read in the communities and news.I don’t understand why there still no official announcement as a warning from the Archlinux team at https://archlinux.org/news/ . Is there a different place for security news specifically about the AUR to subscribe to? EDIT: https://archlinux.org/news/active-aur-malicious-packages-incident/ They did it, an official message.
The fact that the Arch maintainers seem to prefer Reddit over their own fucking news channel is what made me switch from Arch years ago. I got sick of upstream breaking changes fucking my system because they wouldn’t notify people through official channels, only to find it later on /r/archlinux 🙄🙄🙄
What are you using now?
After the end of Win10 I moved to arch but I think my week end will be filled with moving again. ^^
On my desktop, CachyOS 💀
It was years ago when Arch pissed me off, but I couldn’t resist Arch-based distros forever. So far, I haven’t been burned.
On my laptop, Asahi Linux, which is basically Fedora ARM with a custom kernel. I’d recommend Fedora to most general users.
They made an announcement though
deleted by creator
This is a reminder to everyone to only install from the AUR for absolutely necessary stuff only, and only if you trust the maintainer.
Unfortunately not foolproof either. I have no infected packages that I know of because I happen to be on a new install, but I caught wind of the LAST AUR botnet infiltration and switched to flatpaks or source builds. Since then I drifted back to AUR for convenience. I thought I was being clever only using AUR packages when I could be “sure” the author of the original software package pushed to AUR, and this was easy since devs who build on Arch typically recommend AUR whether they maintain the package or not. Today I found out spoofing package ownership is apparently easy and so is spoofing git credentials.
I was on Endeavour and it was incredible, but I’m not That Power User and I feel like part of the problem. The worst part of all of this is its owing to an influx of users who want the same ease of use they used to enjoy, but in Windows SOP is installing whatever the fuck you want on Internet Explorer and bugging your sysadmin to fix whatever happens. Its probably really hard to be any kind of FOSS developer right now.
Yes, definitely not foolproof. This is more of a wake up call to be at least careful and reconsider every single AUR package one has installed. For me, I was lucky too. But in my case it wasn’t pure luck that the few AUR packages I have installed aren’t affected. See, because since years using the AUR (sparingly! including my own package :D ) I always feared off orphaned packages and removed them as soon as I could. This incident here is proof I was right.
For some stuff I also prefer the Flatpak, because I do not trust everyone on the AUR, as they operate on root rights! When I brought this up on Endeavor, they disliked my opinion (as a fresh user) and the trusted community members there explained to me that the AUR is way more safe than Flatpak, because there is a trust system of upvotes and everyone can flag the packages, and that Flatpak has a wrong sense of security. That is what they told me and totally ignored my issues with AUR… one of the reasons why I do not visit the EndeavourOS community… I digress…
EDIT: https://archlinux.org/news/active-aur-malicious-packages-incident/ They did it, an official message.
I wish they’d actually explain their findings/attack vectors so that people have a chance to stay ahead of this by reading the PKGBUILDs as recommended.
Useful list for those who do use Arch; I’ve only got like two things from AUR and neither is on that list (although I kinda recognize a couple with slightly different names, like what, knock off plugins for official stuff?)
I got yesterday an email how one of the packages from this list that I used to maintain was adopted.
AUR

Ahh clearly Arch users didn’t RTFM before installing shit. Skill issue.
PS: The above is an invitation to self-care, not an insult.
I must say, Read The Fucking Manual is a bit more clear than Read The Friendly Manual.

I disagree with the post you put here on a single thing: the manual is sometimes bad, by either not describing everything, or being unclear.
Is that worse than not reading it at all? Often it is a lead to something more useful
You know what? You’re right
Best not to read any then, if it might be bad.
I’ve seriously gone through manuals in languages foreign to me and still learnt something from it.
My partner doesn’t and will only use the basic features of tech. I read the manual, and I’m suddenly a wizard because I got two Bluetooth speakers to pair with each other and get stereo from them.
Reading the manual clearly won’t help with the issue here. This is clearly not an appropriate use of RTFM terminology here, because it does not apply. The problem here is not that the user needs to read before asking for help. The problem here is to understand the changes made in the script are malicious. And reading the manual won’t help with that.
At this point, the count stands at 1500+ https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
The AUR is basically just a shortcut for downloading random shit off GitHub.
It gives un-experienced users a false sense of security.
Maybe maintenance of packages shouldn’t just be handed over to newly created accounts. This is a design flaw on AUR’s part. As Linux popularity rises, these types of attacks will just keep growing. There should also be some sort of system where it is easy to verify that the maintainer of the package is also the actual developer. Like brave-bin has brave has the maintainer who are also the creator. Just give a green check mark to them or something.
the AUR ideally should have a dedicated team of moderators of packages round the clock but archlinux is a community distro, and you really shouldn’t trust the AUR implicitly and treat it as literally downloading stuff from the internet through search because that’s what it does most of the time.
I do use AUR though, and only one (obs-studio-liberty) is not endorsed by the programs I use from it
Do you even read the pkgbuild files you DL from the AUR?
yeah
Least surprising thing ever. Nothing is reviewed or approved, not even proforma
GOTDAMN
I learned 10 years ago not to use aur helpers because they hide the sources. Aurutils + vifm baby!
Dang, if only their packages were more up to date maybe this wouldn’t have happened.
AUR
Play stupid games win stupid prizes I guess.
(btw)
Maybe someone here can advise. I ran two of the available “checking” scripts to see if I have any packages installed. Both came up with 1 package I have installed. It is gtkimageview, which is on the list.
However, if I look through the pacman.log I see it was installed on 2024-10 and last upgraded 2025-01. It seems to me that suggests I installed it before this all started, so I’m probably not infected?












