And since git history can be easily fabricated, here are the archive 
links to the malicious code on github repo:

https://archive.ph/yZoOg

https://archive.ph/jsbYo

On 8/29/26 04:02, Saren wrote:
> This package contains a real config of hyprland but it blatantly opens
> up a backdoor for the attacker:
>
> 1. lures user to type sudo password in post-install, and then do
> following 2-5 without user's permissions
>
> 2. installs Tailscale and OpenSSH (--noconfirm), then joins the
> attacker's Tailscale network (--ssh) to bypass firewalls and grant
> remote shell access
>
> 3. adds an attacker ed25519 key to three locations and spawns two root
> sshd instances on ports 3333/4444. Uses fake Arch systemd service names
> to disguise config files in /etc/pacman.d/
>
> 4. installs SUID-root binaries to three paths (/etc, /usr/lib,
> /usr/bin), triggered hourly by an un-stoppable systemd timer. Grants
> wheel users passwordless sudo execution
>
> 5. configures UFW to allow SSH ports and Tailscale IP 100.70.123.108.
> Wipes systemd logs (journalctl --vacuum-time=1s), disables shell
> history, and clears /root and user .bash_history
>
>
> Package URL: https://aur.archlinux.org/packages/hyprland-fixes
>
> Package source repo: https://github.com/iusearch-hyprlandbtw/hyprland-fixes
>
> Source repo snapshot:
> https://drop.wtako.net/file/22927ab5f074e4fafe959de72bb55db7768e1654.zip
> (password: "backdoor" [8 characters]
>
>

Reply via email to