On 10/9/26 10:54 AM, Saren wrote:
For more information, after a simple research, I found that

- AUR user "CxOrg" solely uploads packages with upstream github user is
"ixnewton"

- all of the ixnewton's github repos have commits pushed with message
"Add security audit workflow" 12 hours ago.

On 10/9/26 16:46, Saren wrote:
(Revised due to accidental reply to an old thread)

Package:https://aur.archlinux.org/packages/plasma6-applet-quicklaunch

Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/

Problematic Upstream File:
https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml

The "security-audit.yml" which will be executed in actions runner is
actually extracting API keys and cloud creds and upload them to an
external server. Although I believe that building this package using
PKGBUILD harmless, the package upstream cannot be trusted anymore.

Also note that the package submitter/maintainer may not be affiliated
with the upstream author.


Hi Saren,

Thanks for the report!

I've blocked the "CxOrg" AUR user and I'm currently in the process of deleting every packages that points to a repo containing this malicious file.

Given it's executed on the github action, the PKGBUILD itself should probably be safe indeed, but let's take no chances.

I will also report the repository to GitHub and contact the maintainer.

--
Regards,
Robin Candau / Antiz

Attachment: OpenPGP_0xFDC3040B92ACA748.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to