Post #3300504
2026-06-12 11:48 UTC
AUR “packages” are just a recipe file that runs some commands that sources packages from somewhere else and builds them then puts them in the format required by the AUR package manager.
Normally it’s a source tarball downloaded directly from the project’s Git repo. But it can also fetch and install a binary package (for closed source software). Or it can install Node modules, or Python modules etc.
Point is, you can’t inject a script directly in AUR itself. You could add the malicious code directly to the recipe file but it would be obvious. You could also download a zip with the malware directly, but it would also be obvious.
So what they do is add the malware to modules published on another platform, and they’re downloaded indirectly, as a dependency of the Nth grade.
It’s very hard to detect, you can’t really notice this kind of attack with a glance at the recipe.
Replies (1)
-
@placebo@lemmy.zip 2026-06-12 17:12
I see. Thanks for the explanation.