Hi, Arch Linux CN member Saren identified hundreds of potential malicious AUR package updates uploaded recently using an LLM agent [1]. In many of these cases, a malicious ELF executable (~50KB size) is uploaded to the package.
I cannot verify all of these LLM reports, but many appear to be true. Here are some of examples I manually verified: android-riscv64-libxinerama python-roman-numerals editorconfiger deeploy-bin lyrical-git calendula-git I presume AUR admins are somewhat aware of the situation as I see some packages have already been reverted and individual reports in this mailist. But I just wanted to make you aware of the scale of this new wave of attacks. [1] https://wtako.net/services/aur-audit Regards, cuihao
