Lemmy | Lama Corp.
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemy.lol to Linux@programming.dev · 15 hours ago

Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages

linuxiac.com

external-link
message-square
46
link
fedilink
  • cross-posted to:
  • linux@lemmy.ml
177
external-link

Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages

linuxiac.com

cm0002@lemy.lol to Linux@programming.dev · 15 hours ago
message-square
46
link
fedilink
  • cross-posted to:
  • linux@lemmy.ml
Arch contributors are cleaning up a malware incident in the AUR after suspicious updates appeared across several user-maintained packages.
  • FiniteBanjo@programming.dev
    link
    fedilink
    arrow-up
    17
    ·
    edit-2
    12 hours ago

    Users can check if they’re already compromised with pacman -Q | grep alvr I think maybe? EDIT: No, sorry, alvr was just one of countless affected packages. Also, several is an understatement since a huge number of packages are affected.

    Post with more information here: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

    • TheDuke@europe.pub
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 hours ago

      Oh my, I’m new to Linux and I use CachyOS for my gaming rig at home. Most of the time I have no idea what I’m doing, but shit runs well and I’m happy about it. But how the hell do I check my noob ass if it’s compromised?!

    • Grass@sh.itjust.works
      link
      fedilink
      arrow-up
      5
      ·
      13 hours ago

      alvr as in the vr streaming program for standalone headsets? that’s kind of a niche among niches. Linux VR users with standalone vr headsets that use that specific method.

      • webghost0101@sopuli.xyz
        link
        fedilink
        arrow-up
        18
        ·
        13 hours ago

        Sweats in “linux vr is one of my current hobby projects”

        • Grass@sh.itjust.works
          link
          fedilink
          arrow-up
          5
          ·
          9 hours ago

          it’s going to be year of the linux vr soon anyway

          • django@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            2
            ·
            9 hours ago

            I am so hyped for this actually

      • NOPper@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        5
        ·
        11 hours ago

        I panicked a bit when I saw the news earlier today as one of those niche guys. Then remembered I had removed it for WiVRn a few weeks ago and don’t have anything else off the AUR. Double niche win lol

      • timestatic@feddit.org
        link
        fedilink
        arrow-up
        1
        ·
        9 hours ago

        I actually had the alvr bin aur installed on my old destop machine. Its just the only proper way for me on Quest to properly play any PCVR games. But i haven’t used nor updated that one in a while. My new arch machine luckily doesn’t have this installed but now im freaking out

      • FiniteBanjo@programming.dev
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        13 hours ago

        EDIT: No, sorry, alvr was just one package, there is no specific source for the infection just one or many malicious users: https://gr.ht/aur_pkg_list.txt

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linux@programming.dev

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

  • !linux_memes@programming.dev
  • !linuxphones@lemmy.ca
  • our Matrix group chat
  • !reactos@programming.dev

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 459 users / day
  • 1.02K users / week
  • 4.03K users / month
  • 10.6K users / 6 months
  • 1 local subscriber
  • 13.9K subscribers
  • 3.9K Posts
  • 30.3K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.19
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org