lemmy.grys.it
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Some_Emo_Chick@lemmy.world to Technology@lemmy.worldEnglish · 2 days ago

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

external-link
message-square
8
link
fedilink
  • cross-posted to:
  • linux@lemmy.world
72
external-link

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

www.phoronix.com

Some_Emo_Chick@lemmy.world to Technology@lemmy.worldEnglish · 2 days ago
message-square
8
link
fedilink
  • cross-posted to:
  • linux@lemmy.world
alert-triangle
You must log in or # to comment.
  • Sarothazrom@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    does a linux mint-using idiot need to worry about this, hypothetically speaking?

    • Some_Emo_Chick@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      15 hours ago

      Generally not. The AUR stands for Archlinux User Repository. It’s their repo. Unless added as a source manually, you will never see a package from it.

      • Sarothazrom@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        14 hours ago

        thank you!

    • Syltti@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      This pertains to Arch’s AUR (Arch User Repository). On Mint, nothing you do will interact with the AUR, so you’re perfectly fine.

      • Sarothazrom@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        14 hours ago

        thank you!

  • mal3oon@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 days ago

    Currently you can use https://github.com/lenucksi/aur-malware-check to do a check if you’re infected. My main server was safe, still haven’t tested on my wayland machine though, I went yolo with that one. No important keys at least are there.

  • badgermurphy@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 days ago

    These guys are slacking! Didn’t they read the RFC for this?

    https://www.rfc-editor.org/info/rfc3514/ https://en.m.wikipedia.org/wiki/Evil_bit

    Amateurs!

  • just_another_person@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 days ago

    They should have some sort of static code scanners on the repos at rest at this point that look for certain patterns and issue warnings.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 411 users / day
  • 3.16K users / week
  • 5.55K users / month
  • 11.8K users / 6 months
  • 1 local subscriber
  • 85.4K subscribers
  • 11.3K Posts
  • 133K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org