On 8/1/26 12:38 PM, [email protected] wrote:
On Jul 31, 2026, 7:15 PM, Robin Candau <[email protected]> wrote:On 7/31/26 12:17 PM, firstpick1992 wrote: > Hi, > > The following packages are still infected: > > bili-tools-git > brutefir > cardamum-git > caveman > comodoro-git > deepseek-tui-git > justevery-code > gesso > gsimplecal-git > human-mcp-git > humen-mcp-bin > humen-mcp-git > i3-workspace-switch-git > i915-sriov-dkms > kickthemout-git > kloak-whonix > openrc-manager-gui > python-drastic > tuigreety-bin > zsh-directory-history-git > llama.cpp-ggml > mimosa-git > mingw-w64-vulkan-tools > nimf > noctyra-cli-git > node-llama-cpp > play-git > python-etcd3 > python-twopoint-git > python-vxi11 > rsbep-backup-git > rtk-git > rtv-git > scenecut-extractor > telegram-desktop-futpib-git > tempora-bin > stable-diffusion.cpp-ggml > warp-terminal-dev-bin > warp-terminal-git > wayland-app-launcher-git > weather-display > astro-box > > Regards, > Firstpick > Hi, Thanks for the report! We should have acted on all infected packages now (including the above list). If some packages slipped through, please tell us. -- Regards, Robin Candau / AntizThere is also a pandoc one now, by user alicemarty, which includes a (most likely) malicious file named bundler in sources.Sent a deletion request via aur web interface.
Thanks for the report, deleted! -- Regards, Robin Candau / Antiz
OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
