FediTown
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Some_Emo_Chick@lemmy.world to Technology@lemmy.worldEnglish · 11 days ago

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

external-link
message-square
22
link
fedilink
  • cross-posted to:
  • security@lemmy.ml
  • linux@lemmy.world
  • linux@lemmy.ml
  • archlinux@lemmy.ml
148
external-link

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

Some_Emo_Chick@lemmy.world to Technology@lemmy.worldEnglish · 11 days ago
message-square
22
link
fedilink
  • cross-posted to:
  • security@lemmy.ml
  • linux@lemmy.world
  • linux@lemmy.ml
  • archlinux@lemmy.ml
alert-triangle
You must log in or # to comment.
  • VivianRixia@piefed.social
    link
    fedilink
    English
    arrow-up
    33
    ·
    11 days ago

    Thankfully I’m clear, but I am guilty of haphazardly installing junk from the AUR, I should clean that up and uninstall everything but the stuff I really use.

    • rozodru@piefed.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      11 days ago

      yeah when I was using Arch I was also an AUR junky. if this was happening back then I know I would have 100% been screwed.

  • mal3oon@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    ·
    10 days ago

    Currently you can use https://github.com/lenucksi/aur-malware-check to do a check if you’re infected. My main server was safe, still haven’t tested on my wayland machine though, I went yolo with that one. No important keys at least are there.

  • Lukario@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    13
    ·
    10 days ago

    I don’t use arch, btw.

  • Imgonnatrythis@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    2
    ·
    10 days ago

    This must be fake news because several hundred people told me there is no malware on Linux.

  • northernlights@fedia.io
    link
    fedilink
    arrow-up
    7
    ·
    11 days ago

    how did this happen? the linked thread show people identifying the infected packages and cleaning them up but no word about how it happened or how to prevent it.

    • rozodru@piefed.world
      link
      fedilink
      English
      arrow-up
      29
      ·
      11 days ago

      I think it was essentially orphaned stuff that got “picked up” by a “new maintainer” and that’s how it happened.

      • northernlights@fedia.io
        link
        fedilink
        arrow-up
        4
        ·
        11 days ago

        oh I saw “clang” in the list of packages and got worried

        • Telorand@reddthat.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 days ago

          You’re only affected if you use the AUR. As far as I understand it, the core packages themselves are fine, so this is more of a MitM attack, where somebody compromised the package download streams

          • cobalt32@lemmy.blahaj.zone
            link
            fedilink
            English
            arrow-up
            4
            ·
            11 days ago

            This is not a MitM attack.

            • Telorand@reddthat.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              10 days ago

              How is it not? They didn’t take over the core projects, they took over the midstream distribution.

              • northernlights@fedia.io
                link
                fedilink
                arrow-up
                8
                ·
                10 days ago

                A MitM attack defines the attack technique, not the target. It’s when the target wants to connect to something but it connects through you first, and you forward while collecting/altering data. My question was about the attack used. But yeah, a mass takeover of everything orphaned would do it.

  • badgermurphy@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    10 days ago

    These guys are slacking! Didn’t they read the RFC for this?

    https://www.rfc-editor.org/info/rfc3514/ https://en.m.wikipedia.org/wiki/Evil_bit

    Amateurs!

  • DevDave@piefed.social
    link
    fedilink
    English
    arrow-up
    4
    ·
    11 days ago

    Definitely a few unfortunate victims to stuff like libyami if using some sort of shell autocomplete. Few others would likely catch younger people, eg the implied apk side channel deployment packages.

  • Sarothazrom@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    9 days ago

    does a linux mint-using idiot need to worry about this, hypothetically speaking?

    • Syltti@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      9 days ago

      This pertains to Arch’s AUR (Arch User Repository). On Mint, nothing you do will interact with the AUR, so you’re perfectly fine.

      • Sarothazrom@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        9 days ago

        thank you!

    • Some_Emo_Chick@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      6
      ·
      9 days ago

      Generally not. The AUR stands for Archlinux User Repository. It’s their repo. Unless added as a source manually, you will never see a package from it.

      • Sarothazrom@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        9 days ago

        thank you!

  • Tetsuo@jlai.lu
    link
    fedilink
    English
    arrow-up
    2
    ·
    10 days ago

    I wonder if a SteamDeck could somehow get infected this way…

    That would surely be a rather unlikely scenario but it’s interesting.

    • GalacticGrapefruit@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 days ago

      Highly likely, actually. SteamOS is Arch-based, and if a user installs things through the AUR on their deck (like a password manager or a VPN that isn’t part of the official upstream repo), then it would be infected exactly the same as any other Arch-derived OS.

  • Ricky Rigatoni@piefed.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    11 days ago

    O deer

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3.33K users / day
  • 9.66K users / week
  • 15.3K users / month
  • 31.6K users / 6 months
  • 1 local subscriber
  • 85.7K subscribers
  • 17.5K Posts
  • 692K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.worldB
  • L3s@hackingne.ws
  • BE: 0.19.19
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org