On 10/9/26 10:54 AM, Saren wrote:
For more information, after a simple research, I found that- AUR user "CxOrg" solely uploads packages with upstream github user is "ixnewton" - all of the ixnewton's github repos have commits pushed with message "Add security audit workflow" 12 hours ago. On 10/9/26 16:46, Saren wrote:(Revised due to accidental reply to an old thread) Package:https://aur.archlinux.org/packages/plasma6-applet-quicklaunch Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/ Problematic Upstream File: https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml The "security-audit.yml" which will be executed in actions runner is actually extracting API keys and cloud creds and upload them to an external server. Although I believe that building this package using PKGBUILD harmless, the package upstream cannot be trusted anymore. Also note that the package submitter/maintainer may not be affiliated with the upstream author.
Hi Saren, Thanks for the report!I've blocked the "CxOrg" AUR user and I'm currently in the process of deleting every packages that points to a repo containing this malicious file.
Given it's executed on the github action, the PKGBUILD itself should probably be safe indeed, but let's take no chances.
I will also report the repository to GitHub and contact the maintainer. -- Regards, Robin Candau / Antiz
OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
