AUR has been hit with malware
Per the CachyOS subreddit:
"As the title states, the Arch AUR has been hit by a huge malware infection campaign over the last couple of days. There's an earlier post referring to alvr. That's not the only package it's hundreds of them, many of them Aur packages average people would install like apple-music-desktop.
I don't have the full details of the scope of the malware campaign. I know it's a credential stealer so it steals ssh keys and browser login info and apparently has rootkit potential.
This was widespread and targeted orphaned packages. Aur for some reason allows other people to take over existing projects.
The bottom line is if you used the aur over the last couple of days you may have been infected and the problem with taking over orphaned packages I believe remains. I personally would not use the Aur for the foreseeable future, and ideally not at all. It's a security risk."
There is a script that you can run on your machine to detect if you have a package that is known to have been infected which you can view here. I have also linked the subreddit post here.
Just download it, make it executable and run the script with sudo and let it run, it will tell you what it found once it's complete.
Pls reblog to signal boost!!
























