Elektrine lite

← Feed

@lemmyvore@feddit.nl

Post #3300504

2026-06-12 11:48 UTC

AUR “packages” are just a recipe file that runs some commands that sources packages from somewhere else and builds them then puts them in the format required by the AUR package manager. Normally it’s a source tarball downloaded directly from the project’s Git repo. But it can also fetch and install a binary package (for closed source software). Or it can install Node modules, or Python modules etc. Point is, you can’t inject a script directly in AUR itself. You could add the malicious code directly to the recipe file but it would be obvious. You could also download a zip with the malware directly, but it would also be obvious. So what they do is add the malware to modules published on another platform, and they’re downloaded indirectly, as a dependency of the Nth grade. It’s very hard to detect, you can’t really notice this kind of attack with a glance at the recipe.

Replies (1)