The Arch Linux team has removed three malicious packages from the AUR package repository.

The packages posed as browser modifications but downloaded and installed a RAT from GitHub.

lists.archlinux.org/archives/l

Follow

@campuscodi Wow. Well I suppose this is why the AUR is separate from official Arch packages.
When I ran Arch Linux, I never used the AUR, out of worry that I might download something like one of these.

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml