Crony's Dungeon
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemy.lol to Linux@programming.dev · 4 days ago

Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages

linuxiac.com

external-link
message-square
69
link
fedilink
209
external-link

Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages

linuxiac.com

cm0002@lemy.lol to Linux@programming.dev · 4 days ago
message-square
69
link
fedilink
Arch contributors are cleaning up a malware incident in the AUR after suspicious updates appeared across several user-maintained packages.
  • FiniteBanjo@programming.dev
    link
    fedilink
    arrow-up
    13
    ·
    edit-2
    3 days ago

    Users can check if they’re already compromised with pacman -Q | grep alvr I think maybe? EDIT: No, sorry, alvr was just one of countless affected packages. Also, several is an understatement since a huge number of packages are affected.

    Post with more information here: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

    • TheDuke@europe.pub
      link
      fedilink
      English
      arrow-up
      4
      ·
      3 days ago

      Oh my, I’m new to Linux and I use CachyOS for my gaming rig at home. Most of the time I have no idea what I’m doing, but shit runs well and I’m happy about it. But how the hell do I check my noob ass if it’s compromised?!

      • FiniteBanjo@programming.dev
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        3 days ago

        I’m not real clear on if this is the case but you could try:

        1. Have you installed or updated from the AUR before, such as with Yay? Specifically after June 5th? If so, check this list or the post above for a list of compromised packages. https://gr.ht/aur_pkg_list.txt

        2. Maybe pacman -Q | grep atomic-lockfile because that appears to be what the threat actor is installing but I’m not really sure if that’s how it works…?

        EDIT: If you really want to play it safe then you could try yay -R $(pacman -Qmq) to remove every aur package and wait out the storm, just be careful to backup important files.

    • Grass@sh.itjust.works
      link
      fedilink
      arrow-up
      5
      ·
      3 days ago

      alvr as in the vr streaming program for standalone headsets? that’s kind of a niche among niches. Linux VR users with standalone vr headsets that use that specific method.

      • webghost0101@sopuli.xyz
        link
        fedilink
        arrow-up
        14
        ·
        3 days ago

        Sweats in “linux vr is one of my current hobby projects”

        • Grass@sh.itjust.works
          link
          fedilink
          arrow-up
          5
          ·
          3 days ago

          it’s going to be year of the linux vr soon anyway

          • django@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            2
            ·
            3 days ago

            I am so hyped for this actually

      • FiniteBanjo@programming.dev
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        3 days ago

        EDIT: No, sorry, alvr was just one package, there is no specific source for the infection just one or many malicious users: https://gr.ht/aur_pkg_list.txt

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • our Matrix group chat
  • !reactos@programming.dev

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 377 users / day
  • 1.32K users / week
  • 4.05K users / month
  • 9.16K users / 6 months
  • 1 local subscriber
  • 14K subscribers
  • 4.65K Posts
  • 31.4K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.13
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org