lidstah's lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Some_Emo_Chick@lemmy.world to Technology@lemmy.worldEnglish · 14 days ago

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

external-link
message-square
13
link
fedilink
87
external-link

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

Some_Emo_Chick@lemmy.world to Technology@lemmy.worldEnglish · 14 days ago
message-square
13
link
fedilink
alert-triangle
You must log in or # to comment.
  • mal3oon@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    14 days ago

    Currently you can use https://github.com/lenucksi/aur-malware-check to do a check if you’re infected. My main server was safe, still haven’t tested on my wayland machine though, I went yolo with that one. No important keys at least are there.

  • Lukario@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    10
    ·
    14 days ago

    I don’t use arch, btw.

  • Imgonnatrythis@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    2
    ·
    14 days ago

    This must be fake news because several hundred people told me there is no malware on Linux.

  • just_another_person@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    14 days ago

    They should have some sort of static code scanners on the repos at rest at this point that look for certain patterns and issue warnings.

    • Tetsuo@jlai.lu
      link
      fedilink
      English
      arrow-up
      1
      ·
      14 days ago

      I wish it was that simple but I doubt there is any scanner that can differentiate between legitimate and malicious code.

      Maybe an AI but even then it would probably be quite unreliable.

  • badgermurphy@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    14 days ago

    These guys are slacking! Didn’t they read the RFC for this?

    https://www.rfc-editor.org/info/rfc3514/ https://en.m.wikipedia.org/wiki/Evil_bit

    Amateurs!

  • Sarothazrom@lemmy.world
    cake
    link
    fedilink
    English
    arrow-up
    3
    ·
    13 days ago

    does a linux mint-using idiot need to worry about this, hypothetically speaking?

    • Some_Emo_Chick@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      4
      ·
      12 days ago

      Generally not. The AUR stands for Archlinux User Repository. It’s their repo. Unless added as a source manually, you will never see a package from it.

      • Sarothazrom@lemmy.world
        cake
        link
        fedilink
        English
        arrow-up
        3
        ·
        12 days ago

        thank you!

    • Syltti@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      13 days ago

      This pertains to Arch’s AUR (Arch User Repository). On Mint, nothing you do will interact with the AUR, so you’re perfectly fine.

      • Sarothazrom@lemmy.world
        cake
        link
        fedilink
        English
        arrow-up
        2
        ·
        12 days ago

        thank you!

  • Tetsuo@jlai.lu
    link
    fedilink
    English
    arrow-up
    2
    ·
    13 days ago

    I wonder if a SteamDeck could somehow get infected this way…

    That would surely be a rather unlikely scenario but it’s interesting.

    • GalacticGrapefruit@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 days ago

      Highly likely, actually. SteamOS is Arch-based, and if a user installs things through the AUR on their deck (like a password manager or a VPN that isn’t part of the official upstream repo), then it would be infected exactly the same as any other Arch-derived OS.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1.08K users / day
  • 2.35K users / week
  • 6.32K users / month
  • 9.65K users / 6 months
  • 1 local subscriber
  • 85.7K subscribers
  • 1.28K Posts
  • 8.69K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.worldB
  • BE: 0.19.19
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org