Hi, 27 more infected AUR packages contain malware executed via sudo during builds:
aic94xx-firmware-bin aur-scanner-bin debtap-bin hexchat-bin fvs2-bin gnu-netcat-bin gtk2-ng-git-bin howdy-next-bin hyprkeys-git-bin noctalia-git-bin nomacs-bin octopi-bin aurutils-bin plasma6-applets-appgrid-bin proton-rtsp pwvucontrol-bin qt5-location-bin qt5-sensors-bin qt5-websockets-bin ttf-symbola-bin woeusb-ng-bin xfwm4-themes-bin xclicker-bin xdg-terminal-exec-bin linux-cachyos-bin paru-git-bin syncthingtray-qt6-bin > > Hi, > > 19 more infected AUR packages contain malware executed via sudo during builds: > > accounts-qml-module-bin > arch-update-bin > aur-sync-vote-bin > bridge-utils-bin > byobu-bin > fsearch-bin > gtk-engine-murrine-bin > gtk2-bin > http-parser-bin > jellium-desktop-git-bin > mangowm-bin > mbedtls2-bin > openssl-1.1-bin > plasma6-applets-panel-colorizer-bin > python-inputs-bin > python-steam-bin > splix-bin > tuxmanager-bin > grub-customizer-bin > > > Robin Candau <[email protected]> schrieb am Freitag, 31. Juli 2026 um 19:32: > > > On 7/31/26 12:17 PM, firstpick1992 wrote: > > > Hi, > > > > > > The following packages are still infected: > > > > > > bili-tools-git > > > brutefir > > > cardamum-git > > > caveman > > > comodoro-git > > > deepseek-tui-git > > > justevery-code > > > gesso > > > gsimplecal-git > > > human-mcp-git > > > humen-mcp-bin > > > humen-mcp-git > > > i3-workspace-switch-git > > > i915-sriov-dkms > > > kickthemout-git > > > kloak-whonix > > > openrc-manager-gui > > > python-drastic > > > tuigreety-bin > > > zsh-directory-history-git > > > llama.cpp-ggml > > > mimosa-git > > > mingw-w64-vulkan-tools > > > nimf > > > noctyra-cli-git > > > node-llama-cpp > > > play-git > > > python-etcd3 > > > python-twopoint-git > > > python-vxi11 > > > rsbep-backup-git > > > rtk-git > > > rtv-git > > > scenecut-extractor > > > telegram-desktop-futpib-git > > > tempora-bin > > > stable-diffusion.cpp-ggml > > > warp-terminal-dev-bin > > > warp-terminal-git > > > wayland-app-launcher-git > > > weather-display > > > astro-box > > > > > > Regards, > > > Firstpick > > > > > > > Hi, > > > > Thanks for the report! > > > > We should have acted on all infected packages now (including the above > > list). If some packages slipped through, please tell us. > > > > -- > > Regards, > > Robin Candau / Antiz > > >
