On 8/1/26 1:03 PM, firstpick1992 wrote:
Hi, 19 more infected AUR packages contain malware executed via sudo during builds: accounts-qml-module-bin arch-update-bin aur-sync-vote-bin bridge-utils-bin byobu-bin fsearch-bin gtk-engine-murrine-bin gtk2-bin http-parser-bin jellium-desktop-git-bin mangowm-bin mbedtls2-bin openssl-1.1-bin plasma6-applets-panel-colorizer-bin python-inputs-bin python-steam-bin splix-bin tuxmanager-bin grub-customizer-bin
Hi, Thanks for the report. I acted on those (deleted the package and banned the account).For the record, those are all new packages (not orphaned packages being adopted). I assume more will come, we'll clean those as soon as possible.
In the mean time stay vigilant, probably refrain from installing freshly pushed new packages from the AUR for now.
-- Regards, Antiz / Robin Candau
OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
