https://aur.archlinux.org/cgit/aur.git/tree/x11-qemu-validation.install?h=x11-qemu-validation

The package names itself for validating qemu config, but from the 
postinstall script, it does the following
1. add a sudo user with hardcoded password
2. installs, enables and starts sshd with "PasswordAuthentication yes" 
and "PermitRootLogin no"

It's simple script but what it claims to do (validation of x11 or qemu) 
has no relation to what it does (creating a backdoor).
Therefore I think is package is likely malicious, and I doubt whether 
this AUR user can be trusted.


Reply via email to