{"id":178196,"date":"2025-07-19T22:21:09","date_gmt":"2025-07-19T22:21:09","guid":{"rendered":"https:\/\/linuxiac.com\/?p=178196"},"modified":"2025-07-20T16:52:40","modified_gmt":"2025-07-20T16:52:40","slug":"malware-discovered-in-arch-linux-aur-packages","status":"publish","type":"post","link":"https:\/\/linuxiac.com\/malware-discovered-in-arch-linux-aur-packages\/","title":{"rendered":"Malware Discovered in Arch Linux AUR Packages"},"content":{"rendered":"\n<p>If you are an Arch user, you know &#8211; <a href=\"https:\/\/aur.archlinux.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">AUR<\/a> (Arch User Repository) is a double-edged sword\u2014it\u2019s incredibly useful but requires caution. Unfortunately, that caution was warranted yet again this week when three AUR packages were found to contain malware.<\/p>\n\n\n\n<p>The issue came to light on July 16 when a user uploaded a malicious package, <code>librewolf-fix-bin<\/code>, to the AUR. Within hours, two more packages\u2014<code>firefox-patch-bin<\/code> and <code>zen-browser-patched-bin<\/code>\u2014followed, all traced back to the same bad actor.<\/p>\n\n\n\n<p>Security researchers quickly identified the threat: a Remote Access Trojan (RAT) hidden in a script pulled from a GitHub repository. For those unfamiliar, a RAT is no joke\u2014it can grant attackers full control over an infected system, enabling them to steal data, install additional malware, or spy on users.<\/p>\n\n\n\n<p>Thankfully, the Arch Linux security team responded promptly as soon as they became aware of the issue. By July 18, all three malicious packages had been removed from AUR. However, if you installed any of these <em>before<\/em> they were removed, your system could still be at risk. So, what should you do?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Remove them immediately\u2014don\u2019t wait.<\/li>\n\n\n\n<li>Check for signs of compromise\u2014unusual network activity, unexpected processes, or unfamiliar files could be red flags.<\/li>\n\n\n\n<li>Consider a more thorough security sweep\u2014malware like this can linger if not completely removed.<\/li>\n<\/ul>\n\n\n\n<p>This isn\u2019t the first time malicious packages have slipped into the AUR, and (probably) it won\u2019t be the last. As you know, AUR is a community-driven repository that&#8217;s separate from the official Arch package sources. In other words, anyone can upload software to it.<\/p>\n\n\n\n<p>Yes, it is an absolute goldmine for extra software and one of the biggest reasons people love Arch, with tens of thousands of packages to choose from. But as this shows, it does come with some risks. So, whenever you <a href=\"https:\/\/linuxiac.com\/how-to-install-aur-packages-in-arch-linux\/\">install something from AUR<\/a>, just be sure to tread carefully.<\/p>\n\n\n\n<p>For more information, <a href=\"https:\/\/lists.archlinux.org\/archives\/list\/aur-general@lists.archlinux.org\/thread\/7EZTJXLIAQLARQNTMEW2HBWZYE626IFJ\/\" target=\"_blank\" rel=\"noreferrer noopener\">here&#8217;s the message<\/a> on Arch&#8217;s mailing list.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Arch Linux deletes three browser-related AUR packages infected with a Remote Access Trojan, urges users to uninstall and check systems for compromise.<\/p>\n","protected":false},"author":10,"featured_media":178199,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,5],"tags":[4264,4487],"class_list":["post-178196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-os","category-news","tag-arch-linux","tag-aur"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts\/178196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/comments?post=178196"}],"version-history":[{"count":0,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts\/178196\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/media\/178199"}],"wp:attachment":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/media?parent=178196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/categories?post=178196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/tags?post=178196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}