On 9/12/26 11:36 AM, Claudia Pellegrino wrote:
Hi Andy,

It looks like the maintainer/upstream dev was compromised with
PolinRider or a variant of that.
https://github.com/OpenSourceMalware/PolinRider
Very good find! One of the artifacts to which the malicious code was appended (`postcss.config.js`) even matches. The WOFF one doesn’t.

It’s definitely possible that the upstream dev has been compromised and hasn’t even noticed.


Regards
Claudia


It's the community that makes it work, and through these trying times, the community has shown its metal and gone above and beyond in keeping AUR safe.

Claudia has been an amazing Maestro, orchestrating the defense. (as well as all others, unnamed, with a hand in providing a solid defense)

  Thanks to all for helping guide AUR through the chaos.

Platitudes aside, we need to be forward thinking on this, to the greatest extent possible. Not just due to the foreseeable future threats, but given the massive increase in capabilities to carry out exploits and poisonings the AI models have placed in the hands of every wanna-be malicious actor.

  An article this past week on The Register drove that point home:

https://www.theregister.com/security/2026/09/10/hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script/5295650

Trying to keep up with the onslaught is like drinking from a fire hose. Arch/AUR collectively has the talent to fair better than most, but the reality is it is only going to get worse. The more we can do to protect/prevent against bad actors gaining AUR accounts to use as a platform to carry out malware distribution, the better.

As with all changes there will be a follow-on period to assess how the changes are working. Some will work, some won't, it's an iterative process, that's just the way it goes. But, compared to four months ago, we are in a lot better position today than we were then.

Thank you all for your keen eyes on AUR activity and for your tireless effort to revert commits and delete accounts when problems are identified!


--
David C. Rankin, J.D.,P.E.

Reply via email to