#aur

27 posts · Last used 5d

Back to Timeline
cptn3mo @cptn3m0@procial.tchncs.de · Aug 04, 2026
Upss... Nutzt jemand Arch oder eine Distribution mit Arch? Nutzt ihr das AUR? https://www.heise.de/news/Neue-Malware-Welle-Arch-Linux-blockiert-AUR-Updates-11395880.html #arch #gnu #linux #aur #malware
0
1
0
G4Media 📰 @G4Media@mastodon.world · Aug 08, 2026
Partidul extremist #AUR (#AlianțaPentruUnireaRomânilor) deschide un nou front împotriva Strategiei privind biodiversitatea: reclamă 71.000 💶#EUR către „firme private”, după ce a atacat la ⚖️#CCR (⚖️#CurteaConstituțională) legea legată de un jalon #PNRR (#PlanulNaționalDeRedresareȘiReziliență) de 972 de milioane 💶#EUR. 🔗 https://wp.me/p9KpFA-5shF #Știri #România #Extremism
0
0
5
Verfassungklage@troet.cafe @Verfassungklage@troet.cafe · Aug 05, 2026
#Arch #Linux zieht die Notbremse nach Angriffen auf das #AUR #Arch_Linux reagiert auf #Sicherheitsvorfälle im AUR. Die Übernahme verwaister #Pakete bleibt vorerst deaktiviert. Die Entwickler griffen nach einer Serie verdächtiger #Paketübernahmen ein. Hintergrund sind manipulierte Änderungen an bislang verwaisten AUR-Paketen. Bis auf Weiteres können deshalb keine neuen Pakete übernommen werden. https://fosstopia.de/arch-linux-zieht-die-notbremse/
2
0
3
basti @basti_sb@mastodon.social · Aug 04, 2026
Ja, wenn sich da jeder bedienen kann, ist doch klar, was dann irgendwann passieren kann. Darüber wurde schon früher diskutiert. #linux #arch #AUR Neue Malware-Welle: Arch Linux blockiert AUR-Updates https://www.heise.de/news/Neue-Malware-Welle-Arch-Linux-blockiert-AUR-Updates-11395880.html Erneut verbreitet sich Malware über Arch User Repositorys. Daher gibt es vorerst überhaupt keine Updates für AUR.
0
0
0
Droppie @MsDropbear42@blahaj.zone · Aug 02, 2026
whilst i came up with an entirely different outcome [i would never ever choose the windoze of penguins, ugh, & i am not a gamer, so care nada about any of that associated crap], some of his thinking matches mine https://www.howtogeek.com/after-5-years-of-using-arch-linux-i-quit/ though i still have ​:archlinux:​ installed on my main pooter's sda, & whilst it is still very reliable for me, the friction from the routine maintenance [he listed some of the items / actions, but there's others too] has been a bit of a drag for me for some years now, plus the ongoing #AUR attacks necessitate a perpetually heightened defensive posture that's tiring, & to which i chose eventually to respond to by replacing most of my AUR pkgs with #flatpak or #distrobox ones, or in several cases nothing at all [ie, i chose to just abandon some apps altogether]. so for a couple of months now [after more than a year in various VMs], my delightful daily penguin is the immutable atomic alpha ​:kde:​ ​:linux:​, on sdc. it is really pleasant to use, albeit ofc i needed to adjust several of my workflows to accommodate its RO base. my sdb remains largely empty atm, but once it reaches Beta i hope to install ​:opensuse:​ kalpa here unfortunately my old 2011 Dell xps-15 lappy is "stuck" with Arch, coz it only has bios not uefi boot, which eliminates both of those atomics, alas #DropbearPooterising #Linux #LinuxWomen #FOSS:kde:​ ​:linux:#KDELinux | ​:archlinux:​ ​:kde:​ ​:plasma:#ArchLinux #KDEPlasma:opensuse:#Kalpa | ​:debian:#SparkyLinux | ​:fedora:#Kinoite:firefox_nightly:#FirefoxNightly #FirefoxSecondSidebar #NativeTreeTabs
0
14
0
Robert Wolff @mahlzahn@nerdculture.de · Apr 11, 2026
Replying to @mahlzahn@nerdculture.de
Good news for the #ArchLinux users among you: #Censor is now available in the #Arch User Repository (#AUR): https://aur.archlinux.org/packages/censor Your feedback is welcome! Already since version 0.3.0, Censor has been packed for #NixOS: https://search.nixos.org/packages?channel=unstable&show=censor Thanks to @pi_crew@social.project-insanity.org for maintaining! #pdf #redaction #linux #packaging #PKGBUILD #maintenance
1
1
1
JTI @jti42@infosec.exchange · Jul 30, 2026
Looks like the AUR of Arch Linux has drawn another round of fire. This time it appears to be a malware integrated into the build() step that comes with the PKGBUILD repo. Possibly Tor using. If the build() step calls some binary like validator, assembler, optimizer, ... that comes with the AUR repo with sudo and suddenly and unexplained appears in the PKGBUILD be very suspicious. See https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/BU6RECTA5DTJBL7Q4NQI5T3AKIN2FWSF/ (confirmation of scale) and https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/PR77K3SB6RFSTYP3KYOJOOX56SMXGBWO/ (first report) And other related mails of that timespan. Probably a good idea to be extra careful around AUR again. If anyone has taken the malware apart I'd be interested in hearing details... @sodiboo@gaysex.cloud @ifin@infosec.exchange #aur #archLinux #malware #linux #upgrades #threatintel
23
11
27
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social · Jun 12, 2026
Something to consider for the current #aur incident, if you don't want to engage with the javascript ecosystem anyway - add this to your /etc/pacman.conf: IgnorePkg = npm IgnorePkg = bun Also make sure both packages aren't installed already and uninstall if necessary. #archlinux
7
0
4
OpenRGB @OpenRGB@floss.social · Jul 05, 2026
Attention #Arch #ArchLinux #AUR #OpenRGB users! The OpenRGB next branch will soon be merged into master, which means the openrgb-git and all of the openrgb-plugin-git packages will move to the new plugin API, breaking compatibility with the released openrgb package in Arch Linux extra. New AUR packages for the 1.0rc2 plugin releases: openrgb-plugin-e131-receiver openrgb-plugin-effects openrgb-plugin-hardware-sync openrgb-plugin-http-hook openrgb-plugin-scheduler openrgb-plugin-visual-map
3
0
2
UmWerker 🕊 ☮️ 🤘 @UmWerker@hachyderm.io · Jun 29, 2026
Am Freitag den PC frisch mit #ArchLinux installiert. Nach dem #AUR Befall habe ich zwar nichts schädliches gefunden, aber mir ist wohler, auf Nummer sicher zu gehen. Zumal der Torfkopp vorm Monitor es fertig brachte, sich sein /home-Verzeichnis zu löschen 🫣 Jetzt alles neu einrichten ermöglicht, wie jeder Neuanfang, bisheriges zu überdenken. Z.B. #FreeFileSync – eines meiner wichtigsten Programme bisher – will ein uraltes, längst nicht mehr empfohlenes #gtk2 installieren. Da werde ich mir wohl eine neue Strategie überlegen. #Linux #Arch
0
0
1
Urlaub im Userspace @userspace@podcasts.social · Jun 26, 2026
Das #AUR wird mit Malware überschwemmt. KDE Plasma 6.7 erscheint als letzte Version mit X11-Support, doch eine Nachfolge existiert bereits. #NixOS 26.05, #Proxmox Datacenter Manager 1.1 und Mail Gateway 9.1 werden veröffentlicht. #Linux 7.1 erscheint und FreeBSD 15.1 erblickt das Licht. Mit #Bumsrakete gibt es eine gravierende FreeBSD-Sicherheitslücke. Eine von uns allen sehr geschätzte Linux-Distribution erhält nach 17 Jahren ein Update. 🎙️ https://user.space/e021-newsupdate-06-2026-malware-im-aur-linux-7-1-kde-plasma-6-7-nixos-26-05-proxmox-datacenter-manager-1-1/ #ArchWasser
5
0
4
weed stallman @incentive@mastodon.circlewithadot.net · Jun 20, 2026
I deal with the AUR as an Arch user like this: 1.) If a project maintains their own repo, I tend to feel ok using the AUR for it. 2.) For a project either not in the AUR or is but not maintained by the project themselves, I use flatpak if its official, or use distrobox to install the version the project maintains/suggests Never install from the AUR if the project doesn't maintain the repo themselves #arch #aur #distrobox
0
0
0
K-Toast :debian: :archlinux: @rsa@norden.social · Jun 19, 2026
Nachdem #Fedora leider so gar nicht gehalten hat, was ich mit versprach, geht’s jetzt doch zurück zu #CachyOS. Mit ihm habe ich mein Setup am Schnellsten zusammengebaut. Tja, nun…. Aber #AUR bleibt draußen! Dad mache ich liebe alles manuell. #Linux #OSS
0
0
0
Verfassungklage@troet.cafe @Verfassungklage@troet.cafe · Jun 17, 2026
#Linux wird zur Zielscheibe: Was der #AUR-Vorfall wirklich zeigt. Aktuell wird in der Linux-Welt wieder über einen Vorfall rund um das AUR diskutiert. Das #AUR ist eine #Community-Paketquelle für #Arch #Linux und # Systeme wie #CachyOS, #EndeavourOS oder #Manjaro. Für mich zeigt dieser Fall nicht, dass Linux plötzlich unsicher ist. Er zeigt eher etwas anderes: Linux wird beliebter. Und dadurch wird Linux auch interessanter als Ziel. #FrumpelLabs @FrumpelLabs https://youtube.com/watch?v=ZX2MCIQGR5I
0
0
2
Anthropy @anthropy@mastodon.derg.nz · Jun 15, 2026
Boosted by Furbland's Very Cool Account™ @GroupNebula563@mastodon.social

It's easy to dunk on Arch's #AUR issues while ignoring what's going on.

  • It involves some accounts that have been around for years, this is a sophisticated and well-planned attack.

  • As much as AUR is very central to Arch, every big distro has its own 'alternative' package platform, like Fedora's Copr and Ubuntu's PPAs.

  • Despite early discovery and coordinated efforts, it is still ongoing.

I think the rest of the ecosystem should take this as a warning.

Linux is not just magically secure.

39
0
25
Arch Linux :archlinux: @archlinux@fosstodon.org · Jun 15, 2026
15
0
47