I have the impression the user account was "breached".
And I also have the impression it's somehow taking over orphaned packages 
(don't know if this is possible), as it seems I only see this package from it, 
but he now has 3 other packages (that were not changed and seem to be ok, but I 
am not sure)


On Monday, September 14th, 2026 at 10:48 AM, Saren <[email protected]> wrote:

> https://aur.archlinux.org/cgit/aur.git/tree/x11-qemu-validation.install?h=x11-qemu-validation
> 
> The package names itself for validating qemu config, but from the
> postinstall script, it does the following
> 1. add a sudo user with hardcoded password
> 2. installs, enables and starts sshd with "PasswordAuthentication yes"
> and "PermitRootLogin no"
> 
> It's simple script but what it claims to do (validation of x11 or qemu)
> has no relation to what it does (creating a backdoor).
> Therefore I think is package is likely malicious, and I doubt whether
> this AUR user can be trusted.
> 
> 
>

Reply via email to