Elektrine lite

← Feed

@jti42@infosec.exchange

Post #4250893

2026-07-30 18:28 UTC

Looks like the AUR of Arch Linux has drawn another round of fire. This time it appears to be a malware integrated into the build() step that comes with the PKGBUILD repo. Possibly Tor using. If the build() step calls some binary like validator, assembler, optimizer, ... that comes with the AUR repo with sudo and suddenly and unexplained appears in the PKGBUILD be very suspicious. See https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/BU6RECTA5DTJBL7Q4NQI5T3AKIN2FWSF/ (confirmation of scale) and https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/PR77K3SB6RFSTYP3KYOJOOX56SMXGBWO/ (first report) And other related mails of that timespan. Probably a good idea to be extra careful around AUR again. If anyone has taken the malware apart I'd be interested in hearing details... @sodiboo@gaysex.cloud @ifin@infosec.exchange #aur #archLinux #malware #linux #upgrades #threatintel

Replies (2)

  • @jti42@infosec.exchange 2026-07-30 19:23

    @sodiboo@gaysex.cloud @ifin@infosec.exchange this guy here @ysf@chaos.social seems to be looking at the malware: https://gist.github.com/ysf https://chaos.social/@ysf/117005490579901545 And we've learned that it comes with varying SHA256s, i.e. is not just the same binary under different names.

    Open ##4250892

  • @sodiboo@gaysex.cloud 2026-07-31 11:46

    @jti42@infosec.exchange @ifin@infosec.exchange I've updated my post from last time to link to your post about the current incident. but i don't really have any interest in being engaged with it this go around. i'm hoping my reach from last time will help notify at least some AUR users, though.

    Open ##4291062