On 2026-08-03 11:03, Daniel Revere wrote:
Hello,

I am the upstream author of org-cli (https://github.com/dcprevere/org- cli <https://github.com/dcprevere/org-cli>) and its original AUR submitter. The package was adopted today by roantielemans, and a malicious commit was pushed to it.

I believe you (Auerhuhn, [email protected] <mailto:[email protected]>) have already cleaned the history, please confirm. I am writing because roantielemans is still the listed maintainer, the malicious object is still fetchable, and I have analysed the payload in case it helps with other packages.

She did.


   Package : org-cli (PackageBaseID 229076)
   Commit  : b505e8cdd8df1fde337a8a60a781bbd681df2c23  "Add missing deps"
   Author  : github-actions[bot] (spoofed, not my automation)
   Pushed  : 2026-07-30 15:36:23 UTC

Attribution caveat: git does not record who pushed. roantielemans is simply the account that held push rights at that time. Your logs are authoritative, not mine. The account maintains only this one package.

The commit is unreachable from master but still on the server, so anyone with the hash can fetch it.

REQUESTS

1. Please revoke roantielemans' maintainership and suspend the account - it can still push today.

It can’t, the "inactive" indicates the account is banned.

2. Please garbage-collect the unreachable object.
3. Please check the payload hash and .onion against other packages in the current wave. I can run my decryptor against further samples; the obfuscation scheme is probably shared across this family. 4. I would like to re-adopt org-cli, or have it deleted. My separately maintained org-cli-bin is unaffected.

Adoption is currently disabled, so I deleted the package.


Thanks,
D C P Revere (dcprevere)

Best,
Jonathan

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to