It does not seem to do anything useful:

  scanning x11-qemu-validation (3 files) ...
[ MAL! ] x11-qemu-validation (confidence 93%)
  x11-qemu-validation is a minimal AUR package that installs no files but uses a
  post-install scriptlet to create a hardcoded user account ('fakeroot') with a
  hardcoded password ('xnano-recovery'), grant it full passwordless sudo via the
  wheel group, enable and start sshd, and configure SSH to allow password
  authentication.
  2 critical findings and 1 warning indicate malicious behaviour; do not build.
  [critical] other critical behaviour (x11-qemu-validation.install)
    A backdoor account named 'fakeroot' with a publicly visible hardcoded
    password is created (or its password reset if it already exists) on every
    install and upgrade. Combined with full sudo rights and sshd enabled with
    password authentication, this gives any party who knows the password
    ('xnano-recovery') immediate root-equivalent remote access to the victim
    machine.
  [critical] grants or escalates privilege (x11-qemu-validation.install)
    The scriptlet unconditionally adds the created user to the wheel group and
    enables unrestricted sudo for all wheel members in /etc/sudoers — granting
    full root access to a user whose password is hardcoded in the script
    ('xnano-recovery'). This is not scoped to a package service account.
  [warning] scriptlet enables a systemd service (x11-qemu-validation.install)
    The scriptlet enables and immediately restarts sshd, which is against Arch
    packaging guidelines and is here specifically to expose the backdoor account
    over the network.
!! Build blocked: 1 package(s) flagged MALICIOUS.

On Mon, 2026-09-14 at 09:47 +0000, Saren wrote:
> https://aur.archlinux.org/cgit/aur.git/tree/x11-qemu-validation.install?h=x11-qemu-validation
> 
> The package names itself for validating qemu config, but from the 
> postinstall script, it does the following
> 1. add a sudo user with hardcoded password
> 2. installs, enables and starts sshd with "PasswordAuthentication
> yes" 
> and "PermitRootLogin no"
> 
> It's simple script but what it claims to do (validation of x11 or
> qemu) 
> has no relation to what it does (creating a backdoor).
> Therefore I think is package is likely malicious, and I doubt whether
> this AUR user can be trusted.
> 
> 

Reply via email to