Comments on: Arch AUR Under Fire Once More as Malware Resurfaces https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/ All things Linux & Open Source Tue, 05 Aug 2025 00:07:46 +0000 hourly 1 https://wordpress.org/?v=6.8.2 By: T3 https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-75208 Tue, 05 Aug 2025 00:07:46 +0000 https://linuxiac.com/?p=180407#comment-75208 In reply to Anonymous.

if its a debate on security out of the box arch will lose with a default setup. If it is a debate on security after setup on what is required to make selinux or other options work like they should arch will still be one of the worst choices. Heck even linux mint which I do not use pushes official sources for flatpaks and would never include something like aur as a option nor would most other major distros. If we are going to talk about security there are a lot of better options like fedora, ubuntu, opensuse all of which are way more secure with how they do things.

]]>
By: Anonymous https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-75128 Mon, 04 Aug 2025 07:51:31 +0000 https://linuxiac.com/?p=180407#comment-75128 Linux is a tool of freedom, which is determined only by user or user community. The tool is neutral without its value system. So the malware is part of humanity, that’s it.
So, please, debate on which linux distribution is better, is almost meaningless, except the discussion about technology on security.
What I found interesting is the web site hosting anonymous files (https://segs.lol/), which is pretty suspicious.

]]>
By: Mark https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-74983 Sat, 02 Aug 2025 15:57:22 +0000 https://linuxiac.com/?p=180407#comment-74983 In reply to Clark.

Relying on virustotal alone will fail you need people reviewing and approving things also. Malware can evade virus scanner detection with little effort and if you think virustotal is going to protect you from untrustworthy sources you risk being owned. Lots of examples just seen a new one today https://thehackernews.com/2025/08/new-plague-pam-backdoor-exposes.html

]]>
By: Walter https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-74977 Sat, 02 Aug 2025 14:44:12 +0000 https://linuxiac.com/?p=180407#comment-74977 In reply to Anonymous.

It’s definitely possible to set up AppArmor on Arch, but when it comes to SELinux, you’re pretty much out of luck unless you’re willing to do a lot of extra work. Most people stick with Fedora or openSUSE if they need SELinux because it requires a lot of specific configurations for everything on your system to work properly.

]]>
By: Anonymous https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-74935 Sat, 02 Aug 2025 07:35:51 +0000 https://linuxiac.com/?p=180407#comment-74935 In reply to TheBurgerKing.

If it’s a concerted effort, it’s probably a pretty bad one. Most likely it’s just a copycat of the first malware. We’ll probably see a few more over the coming weeks as people think “wow, I can just put malware in the AUR and people will install it? I bet I can beat their garbage dwell time!”.

Unlike the xz backdoor that required befriending a maintainer and spending years to get the malware in upstream package repositories, anyone can put anything in the AUR. You could put malware in yourself right now if you wanted with no effort. Frankly, I’m surprised it even took this long.

]]>
By: Anonymous https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-74932 Sat, 02 Aug 2025 07:33:12 +0000 https://linuxiac.com/?p=180407#comment-74932 In reply to Zephyr.

Did you read the article? There was no malware in the package itself. The package downloaded and executed a malicious Python script from a URL. Even if the AUR attempted to install every package in a sandbox to determine if anything malicious occurred, that would only work for known malware and would be very easy to bypass.

]]>
By: Anonymous https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-74929 Sat, 02 Aug 2025 07:31:19 +0000 https://linuxiac.com/?p=180407#comment-74929 In reply to Matt.

Arch fully supports SELinux, and the package management is not rubbish. The malware was in the AUR, which is user-submitted. It’s akin to some big, centralized anyone-can-add-anything PPA.

I’m pretty sure Debian is the one that is always the last to adopt security features, btw. It was the last to adopt PIE, the last to adopt RELRO, the last to adopt FORTIFY_SOURCE (it still hasn’t fully adopted it), etc.

Not saying that Arch is great and Debian sucks of course. But it’s overly simplistic to say that Arch lacks modern security features or blaming malware in the AUR on Arch when Arch does not manage the AUR.

]]>
By: Cola7 https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-74923 Sat, 02 Aug 2025 04:26:47 +0000 https://linuxiac.com/?p=180407#comment-74923 In reply to Clark.

Those scores mean nothing when most people are not checking anything for malware before or after the install since malware can be loaded even after you install something. The small handful of people that do actually check anything on there are not checking the majority of stuff on there. There is no reason to install anything from this source since almost everything can be installed from official or more trust worthy sources. Even stuff that has been around for awhile can have malicious things added to it by accident from incompetent people or on purpose at a later date usually for money. Unless you know how to audit software properly and even audit the updates with the use of a isolated system then you should probably look else where for software since there are many ways to try and hide things or introduce things that should not exist especially if some real effort is put into it which could easily happen when there are countries like iran, north korea, china and russia that have no problem doing just that for purposes like building up a massive bot network or for other purposes which can be sold or rented out for money which happens way more often then most people are even aware of and the number of devices that have been owned or added for various purposes just keeps on growing.

]]>
By: TheBurgerKing https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-74912 Sat, 02 Aug 2025 02:26:57 +0000 https://linuxiac.com/?p=180407#comment-74912 seems like a concerted effort to try undermine the AUR by bad actors. there are shady applications even on the microsoft windows store and android store abd iOS store that you can easily download that will install all sorts of malware, zero effort to remove those.

]]>
By: Joom https://linuxiac.com/arch-aur-under-fire-once-more-as-malware-resurfaces/#comment-74908 Sat, 02 Aug 2025 01:46:23 +0000 https://linuxiac.com/?p=180407#comment-74908 In reply to Clark.

It seems like you don’t have a lot of experience with the apt or dpkg utilities. Since you don’t seem all that familiar, DEB packages can be downloaded from a repository, and unpacked, without installing them. They’re essentially ZIP files, and inside them is a directory layout that denotes where every single part of the package is installed. On that note, you also don’t seem all that familiar with Arch, because more often than not, a PKGBUILD is just downloading a precompiled binary, and untar’ing it to the proper location. Where you got this idea that what you get isn’t precompiled is unknown to me, but it’s not entirely true.

]]>