Hi,

Arch Linux CN member Saren identified hundreds of potential malicious AUR
package updates uploaded recently using an LLM agent [1]. In many of these
cases, a malicious ELF executable (~50KB size) is uploaded to the package.

I cannot verify all of these LLM reports, but many appear to be true. Here
are some of examples I manually verified:
android-riscv64-libxinerama
python-roman-numerals
editorconfiger
deeploy-bin
lyrical-git
calendula-git

I presume AUR admins are somewhat aware of the situation as I see some
packages have already been reverted and individual reports in this mailist.
But I just wanted to make you aware of the scale of this new wave of
attacks.

[1] https://wtako.net/services/aur-audit

Regards,
cuihao

Reply via email to