Hi,

19 more infected AUR packages contain malware executed via sudo during builds:

accounts-qml-module-bin
arch-update-bin
aur-sync-vote-bin
bridge-utils-bin
byobu-bin
fsearch-bin
gtk-engine-murrine-bin
gtk2-bin
http-parser-bin
jellium-desktop-git-bin
mangowm-bin
mbedtls2-bin
openssl-1.1-bin
plasma6-applets-panel-colorizer-bin
python-inputs-bin
python-steam-bin
splix-bin
tuxmanager-bin
grub-customizer-bin


Robin Candau <[email protected]> schrieb am Freitag, 31. Juli 2026 um 19:32:

> On 7/31/26 12:17 PM, firstpick1992 wrote:
> > Hi,
> > 
> > The following packages are still infected:
> > 
> > bili-tools-git
> > brutefir
> > cardamum-git
> > caveman
> > comodoro-git
> > deepseek-tui-git
> > justevery-code
> > gesso
> > gsimplecal-git
> > human-mcp-git
> > humen-mcp-bin
> > humen-mcp-git
> > i3-workspace-switch-git
> > i915-sriov-dkms
> > kickthemout-git
> > kloak-whonix
> > openrc-manager-gui
> > python-drastic
> > tuigreety-bin
> > zsh-directory-history-git
> > llama.cpp-ggml
> > mimosa-git
> > mingw-w64-vulkan-tools
> > nimf
> > noctyra-cli-git
> > node-llama-cpp
> > play-git
> > python-etcd3
> > python-twopoint-git
> > python-vxi11
> > rsbep-backup-git
> > rtk-git
> > rtv-git
> > scenecut-extractor
> > telegram-desktop-futpib-git
> > tempora-bin
> > stable-diffusion.cpp-ggml
> > warp-terminal-dev-bin
> > warp-terminal-git
> > wayland-app-launcher-git
> > weather-display
> > astro-box
> > 
> > Regards,
> > Firstpick
> > 
> 
> Hi,
> 
> Thanks for the report!
> 
> We should have acted on all infected packages now (including the above 
> list). If some packages slipped through, please tell us.
> 
> -- 
> Regards,
> Robin Candau / Antiz
>

Reply via email to