On 8/11/26 9:57 PM, David Woodard wrote:
Apologies if this is the wrong address for such things.

[storageexplorer-bin](https://aur.archlinux.org/pkgbase/storageexplorer- bin <https://aur.archlinux.org/pkgbase/storageexplorer-bin>) contains a hidden copy of "optimizer".

While using Claude to build a tool to self-protect from the AUR malware, it discovered a probable hit on a malware entry that made it in.  After looking at what the script is doing, I'm suspecting the current AUR entry is a phase one of a two phase attack plan where it's hiding the embedded optimizer binary's presence from scanners and will do an update later or use another path to activate.

Thanks,
David


Hi,

It's apparently an infected package we missed when cleaning up after the recent attack wave. I deleted it.

Thanks for the report.

--
Regards,
Robin Candau / Antiz

Attachment: OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to