On 03/08/2026 10:03, Daniel Revere wrote:
Hello,
Hi,
I am the upstream author of org-cli (https://github.com/dcprevere/org- cli <https://github.com/dcprevere/org-cli>) and its original AUR submitter. The package was adopted today by roantielemans, and a malicious commit was pushed to it.
Thank you for the report
I believe you (Auerhuhn, [email protected] <mailto:[email protected]>) have already cleaned the history, please confirm. I am writing because roantielemans is still the listed maintainer, the malicious object is still fetchable,
[..]>
REQUESTS1. Please revoke roantielemans' maintainership and suspend the account - it can still push today.2. Please garbage-collect the unreachable object.3. Please check the payload hash and .onion against other packages in the current wave. I can run my decryptor against further samples; the obfuscation scheme is probably shared across this family. 4. I would like to re-adopt org-cli, or have it deleted. My separately maintained org-cli-bin is unaffected.
The AUR is in maintenance [1] - this is expected while we clean up.I understand the intention to provide as much details as possible to assist on this malicious clean up effort but please don't send in the ML the hash of a known malicious commit - thanks
PS: I've clean this up and now shouldn't be fetch-able.[1]: https://lists.archlinux.org/archives/list/[email protected]/message/YPJ3FQYJTJXXY3RUXCYLMHUKHLIUNVFF/
--
Leonidas Spyropoulos
Developer & DevOps
PGP: 59E43E106B247368
244740D17C7FD0EC
OpenPGP_0x244740D17C7FD0EC.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
