Hi Saren,

Thanks for the report.
I have suspended the account and nuked the package (overwriting history).

Thank you for being vigilant and paying attention.


Regards
Claudia


On 28.08.26 10:02 PM, Saren wrote:
This package contains a real config of hyprland but it blatantly opens
up a backdoor for the attacker:

1. lures user to type sudo password in post-install, and then do
following 2-5 without user's permissions

2. installs Tailscale and OpenSSH (--noconfirm), then joins the
attacker's Tailscale network (--ssh) to bypass firewalls and grant
remote shell access

3. adds an attacker ed25519 key to three locations and spawns two root
sshd instances on ports 3333/4444. Uses fake Arch systemd service names
to disguise config files in /etc/pacman.d/

4. installs SUID-root binaries to three paths (/etc, /usr/lib,
/usr/bin), triggered hourly by an un-stoppable systemd timer. Grants
wheel users passwordless sudo execution

5. configures UFW to allow SSH ports and Tailscale IP 100.70.123.108.
Wipes systemd logs (journalctl --vacuum-time=1s), disables shell
history, and clears /root and user .bash_history


Package URL: https://aur.archlinux.org/packages/hyprland-fixes

Package source repo: https://github.com/iusearch-hyprlandbtw/hyprland-fixes

Source repo snapshot:
https://drop.wtako.net/file/22927ab5f074e4fafe959de72bb55db7768e1654.zip
(password: "backdoor" [8 characters]



Attachment: OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to