Live data from Hacker News

AUR packages compromised with Infostealer and Rootkit

discourse.ifin.network

121–130 of 234 posts

Re: AUR packages compromised with Infostealer and Rootkit

#122
post #87
post #83

Earlier quoted context omitted.

> How would that even work? Are you seriously asking how would sharing short text notes over internet work? If you need to be 100% git-centric, you can have git repo for messages. Client will then remember last commit displayed to user and refuse to continue unless latest message was displayed. BTW some AUR clients displayed ArchLinux RSS feed before... Too sad the issue is not even mentioned in the RSS feed...

There's no shortage in ideas of how to make the AUR easier to moderate. A "quarantine button", an invite system, a request system for adoption similiar to how orphan requests work, code review attestations similiar to cargo-crev, pacing controls similiar to those in discourse. There is a shortage however of people skilled enough to implement them (with available time to do so). What we also don't have a shortage of i…

People have all right to be angry if basic responsible adult things like "quarantine the server spreading large amounts of malware" do not happen within the reasonable timespan that passed.

Not even a news. A hint. Nothing. Radio silence.

___

There is a house. It is currently on fire (since over 24h). So far, people have talked about how, conceptually, house fires are bad.

You can still enter the house just fine.

People saying "hey what about locking the door to not trap more people in it" are being shunned for the crime of breaking someones workflow.

The owner of said house is nowhere to be seen.

Passerbys stating "oh my god that house is on fire! get water!" are either ignored or reminded that there is no problem and they should move along.

___

Idk man. I don't think any of this is real.

And I don't even use arch, lol. And after this thing exposed the institutional rot, neither should you or really anyone.

Unless you like ending up locked inside a house fire. I guess they provide warmth in the cold harsh reality of the 2026 internet.

Re: AUR packages compromised with Infostealer and Rootkit

#123
post #89
post #82

Earlier quoted context omitted.

> You have to review the source of every PKGBUILD from the AUR you install, full stop I don't really think this is a solution- the usual workflow for these attacks has been to hide your payload in some dependency. This one is somewhat unusual in that it's just a very lazy `npm install` in the pkgbuild. Pretty much every package repository even outside of AUR has this issue now, and it's not really viable to audit the…

This is an "in addition to" problem though, not an "instead of" problem. Having code reviewed the PKGBUILD doesn't mean the upstream software is safe to use, having reviewed the upstream software and it's dependency tree doesn't mean the PKGBUILD is safe to use.

Also have realized at some point that reviewing the PKGBUILD and code in github repo still doesn't check whether the github release files are compromised.

Re: AUR packages compromised with Infostealer and Rootkit

#124

So what's a solution to this? Install packages like this in Docker containers without network access? I don't think we should assume it's limited to AUR. Every software source should be considered suspect in 2026, particularly with the adoption of vibe coding, and closed software is a bigger mess than open source because it's a black box.

Flatpak

Re: AUR packages compromised with Infostealer and Rootkit

#125
So, could anyone sum up the "Am I owned" part of the problem to check which measures to take?

AFAIK I'm pretty likely owned if all of this is true:

- The following line shows at least one affected package:

  echo "Affected Packages Found:"; comm -12 
- I updated AUR in the last 24 hours

If I did not update AUR, in the last 2 days, it should be ok (at least for this specific problem).

If I don't see affected packages from the line above, it is probably ok, but maybe there are malicious packages that are not listed and yet I'm still be owned, so I have to be careful.

Is that correct and if not, what did I get wrong? And are there any checks that I can perform, that proof the status of the system?

Re: AUR packages compromised with Infostealer and Rootkit

#126
post #62
post #36

Earlier quoted context omitted.

The canonical answer to any concerns with the AUR is always “just read the PKGBUILDs bro”

For every single update, for all your AUR packages, all the time. You know that thing where if you make a security review feature obnoxious, after some time people will just accept everything without even looking? Yeah...

> For every single update, for all your AUR packages, all the time.

Yes, that's what I used to do when I ran Arch. It's usually easy. The PKGBUILD is usually small to begin with and the difference for a new version should normally be something like the URL and the version number and not much else, so you can just diff it against the old version.

Re: AUR packages compromised with Infostealer and Rootkit

#127

So, could anyone sum up the "Am I owned" part of the problem to check which measures to take? AFAIK I'm pretty likely owned if all of this is true: - The following line shows at least one affected package: echo "Affected Packages Found:"; comm -12 - I updated AUR in the last 24 hours If I did not update AUR, in the last 2 days, it should be ok (at least for this specific problem). If I don't see affected packages fro…

Nothing is necessary if you didn't update AUR packages over the last 2 days. If you wait a day further, the maintainers will cleanup these as well, after taht you can upgrade.

Re: AUR packages compromised with Infostealer and Rootkit

#128
post #122
post #87

Earlier quoted context omitted.

There's no shortage in ideas of how to make the AUR easier to moderate. A "quarantine button", an invite system, a request system for adoption similiar to how orphan requests work, code review attestations similiar to cargo-crev, pacing controls similiar to those in discourse. There is a shortage however of people skilled enough to implement them (with available time to do so). What we also don't have a shortage of i…

People have all right to be angry if basic responsible adult things like "quarantine the server spreading large amounts of malware" do not happen within the reasonable timespan that passed. Not even a news. A hint. Nothing. Radio silence. ___ There is a house. It is currently on fire (since over 24h). So far, people have talked about how, conceptually, house fires are bad. You can still enter the house just fine. Peo…

The server actually hosting the rootkit executable is npmjs.com, run by a for-profit company, and they still take about 24h to act on our reports, while reported AUR packages have been processed in about 1-2h by people that work unrelated dayjobs on top of this, to self-subsidize their open source work.

Sorry you're displeased with us not writing blogposts faster on top of all this. The situation is already exhausting enough without people like you.

Re: AUR packages compromised with Infostealer and Rootkit

#129
post #128
post #122

Earlier quoted context omitted.

People have all right to be angry if basic responsible adult things like "quarantine the server spreading large amounts of malware" do not happen within the reasonable timespan that passed. Not even a news. A hint. Nothing. Radio silence. ___ There is a house. It is currently on fire (since over 24h). So far, people have talked about how, conceptually, house fires are bad. You can still enter the house just fine. Peo…

The server actually hosting the rootkit executable is npmjs.com, run by a for-profit company, and they still take about 24h to act on our reports, while reported AUR packages have been processed in about 1-2h by people that work unrelated dayjobs on top of this, to self-subsidize their open source work. Sorry you're displeased with us not writing blogposts faster on top of all this. The situation is already exhaustin…

Look, man, I understand all that, but pulling the plug is something that takes at most 90s. Let's say 300s to add the "Warning: There is an attack. We're working on it. Systems are down for now" box

After that, you have all the time in the world to prioritize dayjobs etc.

It's not about dropping everything and fixing the root cause. It's just about taking stuff offline so that the immediate danger is mitigated.

That is not too much to ask. It's not "people like me" having weird opinions there.

Shut it down. Then fix whenever there is time to do so.

___

But hey. Finally a statement from someone with some amount of position in the org I guess?

I wouldn't want to be in your shoes for sure, but that's beside the point. Nothing here is unreasonable other than the ostrich-style incident response lack-of-process.

And I don't mean stupid corporate process. I mean "common sense adults are in the room" process. Throw waterbucket at burning server reflex.

___

I mean I can see that your userbase absolutely sucks and could imagine that one would be scared of getting roasted for "interrupting their workflow", but this is not the way.

Their workflow is irrelevant.

As said, I'm all here for maintainer empathy, but only after the fire is put out first.

___

Anyway, "institutional rot" is not an insult but a diagnosis. I'd love to be proven wrong on that, but I don't see it.

And trust me, I do know first hand how thankless this non-job is and what hell one goes through. I have skin in the game. I just don't have a horse in the arch race.

Re: AUR packages compromised with Infostealer and Rootkit

#130

Earlier quoted context omitted.

> You have to review the source of every PKGBUILD from the AUR you install, full stop. Yes that includes any updates. But isn’t that also the case for every browser extension, VSCode extension, nuget package, Cargo crate, python package, npm package, etc? (Unless you are running them somewhere without internet access or without access to anything you don’t mind being public?) Maybe it’s not the case for aur, but the…

> isn’t that also the case for every browser extension, VSCode extension, nuget package, Cargo crate, python package, npm package Yes, and all of those have supply chain hacks in them, and have happened within the last year? In this specific case, it's a malicious npm package being installed with official npm tooling in the PKGBUILD. The advantage to the AUR is just that you can reasonably review every PKGBUILD for w…

Curious, in this specific case: if people DID review the PKGBUILD, what exactly would they recognize to spot these packages were compromised ?
Post reply on HN