Hi Saren and others,

thanks for the report. I have suspended the maintainer’s AUR account and nuked the offending AUR package.

Regarding the other three packages owned by the account: at first glance, I can’t find any evidence of malice. I’m going to leave those as is for now.

(The fact that the suspended account keeps owning them until another user requests adoption shouldn’t matter. They can’t push anything, plus it’s how we’ve treated similar cases in past attack waves.)

Thanks again to y’all!


Regards
Claudia


On 14.09.26 11:47 AM, Saren wrote:
https://aur.archlinux.org/cgit/aur.git/tree/x11-qemu-validation.install?h=x11-qemu-validation

The package names itself for validating qemu config, but from the
postinstall script, it does the following
1. add a sudo user with hardcoded password
2. installs, enables and starts sshd with "PasswordAuthentication yes"
and "PermitRootLogin no"

It's simple script but what it claims to do (validation of x11 or qemu)
has no relation to what it does (creating a backdoor).
Therefore I think is package is likely malicious, and I doubt whether
this AUR user can be trusted.

Attachment: OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to