On Jul 31, 2026, 7:15 PM, Robin Candau <[email protected]> wrote:

On 7/31/26 12:17 PM, firstpick1992 wrote:
> Hi,
>
> The following packages are still infected:
>
> bili-tools-git
> brutefir
> cardamum-git
> caveman
> comodoro-git
> deepseek-tui-git
> justevery-code
> gesso
> gsimplecal-git
> human-mcp-git
> humen-mcp-bin
> humen-mcp-git
> i3-workspace-switch-git
> i915-sriov-dkms
> kickthemout-git
> kloak-whonix
> openrc-manager-gui
> python-drastic
> tuigreety-bin
> zsh-directory-history-git
> llama.cpp-ggml
> mimosa-git
> mingw-w64-vulkan-tools
> nimf
> noctyra-cli-git
> node-llama-cpp
> play-git
> python-etcd3
> python-twopoint-git
> python-vxi11
> rsbep-backup-git
> rtk-git
> rtv-git
> scenecut-extractor
> telegram-desktop-futpib-git
> tempora-bin
> stable-diffusion.cpp-ggml
> warp-terminal-dev-bin
> warp-terminal-git
> wayland-app-launcher-git
> weather-display
> astro-box
>
> Regards,
> Firstpick
>

Hi,

Thanks for the report!

We should have acted on all infected packages now (including the above
list). If some packages slipped through, please tell us.

--
Regards,
Robin Candau / Antiz

There is also a pandoc one now, by user alicemarty, which includes a (most 
likely) malicious file named bundler in sources.
Sent a deletion request via aur web interface.

Reply via email to