On 03/08/2026 10:03, Daniel Revere wrote:
Hello,

Hi,

I am the upstream author of org-cli (https://github.com/dcprevere/org- cli <https://github.com/dcprevere/org-cli>) and its original AUR submitter. The package was adopted today by roantielemans, and a malicious commit was pushed to it.

Thank you for the report

I believe you (Auerhuhn, [email protected] <mailto:[email protected]>) have already cleaned the history, please confirm. I am writing because roantielemans is still the listed maintainer, the malicious object is still fetchable,
[..]>
REQUESTS

1. Please revoke roantielemans' maintainership and suspend the account - it can still push today.
2. Please garbage-collect the unreachable object.
3. Please check the payload hash and .onion against other packages in the current wave. I can run my decryptor against further samples; the obfuscation scheme is probably shared across this family. 4. I would like to re-adopt org-cli, or have it deleted. My separately maintained org-cli-bin is unaffected.


The AUR is in maintenance [1] - this is expected while we clean up.

I understand the intention to provide as much details as possible to assist on this malicious clean up effort but please don't send in the ML the hash of a known malicious commit - thanks

PS: I've clean this up and now shouldn't be fetch-able.

[1]: https://lists.archlinux.org/archives/list/[email protected]/message/YPJ3FQYJTJXXY3RUXCYLMHUKHLIUNVFF/

--
Leonidas Spyropoulos
Developer & DevOps
PGP: 59E43E106B247368
     244740D17C7FD0EC

Attachment: OpenPGP_0x244740D17C7FD0EC.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to