this post was submitted on 12 Jun 2026
46 points (100.0% liked)

Arch Linux

9793 readers
3 users here now

The beloved lightweight distro

founded 6 years ago
MODERATORS
all 7 comments
sorted by: hot top controversial new old
[–] odseey@lemmy.world 6 points 6 days ago (1 children)

More info here: https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577

Everyone should check and make sure you don't have one of these installed.

[–] darcmage@lemmy.dbzer0.com 6 points 6 days ago* (last edited 6 days ago) (1 children)
[–] bisby@lemmy.world 4 points 6 days ago* (last edited 6 days ago) (1 children)

Oh fun. I had one of the packages installed, but not an infected version, and I hadn't updated it during the window.

Feels like a great reminder to keep a clean minimal system. Why I was keeping vidcutter installed and up to date when the last time I ran it was probably years ago.

[–] darcmage@lemmy.dbzer0.com 2 points 6 days ago (1 children)

I thought for sure I had a few of them since some of the packages looked familiar but everything came out clean. Hopefully it stays that way.

[–] bisby@lemmy.world 2 points 6 days ago (1 children)

My last update to vidcutter was from 2025 (based on my pacman logs). Some tools will scan for "did you install the bad package during the bad time period" and some will scan for "is the bad package name installed at all" - so i was able to identify that vidcutter was installed and I knew that the package names looking familiar made sense, and I was able to manually confirm that I was still clean. And now I have a lot of system pruning to do.

But if you thing some packages look familiar, it might be worth double checking.

[–] darcmage@lemmy.dbzer0.com 2 points 6 days ago

Yeah I looked for them manually before coming across the scripts. I've been pretty careful with the aur and always check the comments on any new package I'm thinking of installing. Also I've gotten into the habit of checking the pkgbuilds after switching to paru from yay.