Have you reported the IPs and Tailscale network to tailscale's abuse team?
On August 28, 2026 8:02:13 PM UTC, Saren <[email protected]> wrote: >This package contains a real config of hyprland but it blatantly opens >up a backdoor for the attacker: > >1. lures user to type sudo password in post-install, and then do >following 2-5 without user's permissions > >2. installs Tailscale and OpenSSH (--noconfirm), then joins the >attacker's Tailscale network (--ssh) to bypass firewalls and grant >remote shell access > >3. adds an attacker ed25519 key to three locations and spawns two root >sshd instances on ports 3333/4444. Uses fake Arch systemd service names >to disguise config files in /etc/pacman.d/ > >4. installs SUID-root binaries to three paths (/etc, /usr/lib, >/usr/bin), triggered hourly by an un-stoppable systemd timer. Grants >wheel users passwordless sudo execution > >5. configures UFW to allow SSH ports and Tailscale IP 100.70.123.108. >Wipes systemd logs (journalctl --vacuum-time=1s), disables shell >history, and clears /root and user .bash_history > > >Package URL: https://aur.archlinux.org/packages/hyprland-fixes > >Package source repo: https://github.com/iusearch-hyprlandbtw/hyprland-fixes > >Source repo snapshot: >https://drop.wtako.net/file/22927ab5f074e4fafe959de72bb55db7768e1654.zip >(password: "backdoor" [8 characters] > >
