Hello,

I am the upstream author of org-cli (https://github.com/dcprevere/org-cli)
and its original AUR submitter. The package was adopted today by
roantielemans, and a malicious commit was pushed to it.

I believe you (Auerhuhn, [email protected]) have already cleaned the
history, please confirm. I am writing because roantielemans is still the
listed maintainer, the malicious object is still fetchable, and I have
analysed the payload in case it helps with other packages.

  Package : org-cli (PackageBaseID 229076)
  Commit  : b505e8cdd8df1fde337a8a60a781bbd681df2c23  "Add missing deps"
  Author  : github-actions[bot] (spoofed, not my automation)
  Pushed  : 2026-07-30 15:36:23 UTC

Attribution caveat: git does not record who pushed. roantielemans is simply
the account that held push rights at that time. Your logs are
authoritative, not mine. The account maintains only this one package.

The commit is unreachable from master but still on the server, so anyone
with the hash can fetch it.

REQUESTS

1. Please revoke roantielemans' maintainership and suspend the account - it
can still push today.
2. Please garbage-collect the unreachable object.
3. Please check the payload hash and .onion against other packages in the
current wave. I can run my decryptor against further samples; the
obfuscation scheme is probably shared across this family.
4. I would like to re-adopt org-cli, or have it deleted. My separately
maintained org-cli-bin is unaffected.

Thanks,
D C P Revere (dcprevere)

Reply via email to