I have the impression the user account was "breached". And I also have the impression it's somehow taking over orphaned packages (don't know if this is possible), as it seems I only see this package from it, but he now has 3 other packages (that were not changed and seem to be ok, but I am not sure)
On Monday, September 14th, 2026 at 10:48 AM, Saren <[email protected]> wrote: > https://aur.archlinux.org/cgit/aur.git/tree/x11-qemu-validation.install?h=x11-qemu-validation > > The package names itself for validating qemu config, but from the > postinstall script, it does the following > 1. add a sudo user with hardcoded password > 2. installs, enables and starts sshd with "PasswordAuthentication yes" > and "PermitRootLogin no" > > It's simple script but what it claims to do (validation of x11 or qemu) > has no relation to what it does (creating a backdoor). > Therefore I think is package is likely malicious, and I doubt whether > this AUR user can be trusted. > > >
