Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Halted

https://www.phoronix.com/news/Arch-Linux-AUR-Adoptions-Halted

32 points · 5 comments · view on lemmy.world

5 Comments

Jayjader@jlai.lu · 5 pts · 35d

I'm starting to think it's time the AUR introduced namespacing packages by the maintainer's AUR username. The single namespace was nice while it lasted, but it seems like we're going to need to get packages based on who's uploading them anyways...

IAmYouButYouDontKnowYet@reddthat.com · 3 pts · 35d (2 replies)

I wonder why Aur is a target.

You think it's Microsoft related?

gid@piefed.blahaj.zone · 10 pts · 35d (1 reply)

Probably because it's an attack vector where the effort required to infiltrate malware is relatively low.

chortle_tortle@mander.xyz · 6 pts · 35d

From the mailing list thread:

For the record, those are all new packages (not orphaned packages being adopted). I assume more will come, we'll clean those as soon as possible.

In the mean time stay vigilant, probably refrain from installing freshly pushed new packages from the AUR for now.

Looking over the list it's almost all git/bin versions of files. So they just added a ton of new packages like hexchat-bin that didn't have those versions before and injected malware.

Valso@lemmy.ml · 1 pts · 25d

I stopped using AUR long before these packages and before the DDOS attacks. Mostly because I started rewriting the code of different applications to compile with QT5 or GTK3. For that I need the source, not what's uploaded on AUR. Which makes me think why I'm still keeping trizen when I don't even use it. 😆