K.S. Bhaskar via plug on 16 Jun 2026 08:31:29 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit


Absolute security does not exist. Ultimately, you have to trust someone, with varying degrees of trust for different sources. There is not a 100% guarantee that a core Debian package, for example, is totally clean.

Regards
- Bhaskar

On Tue, Jun 16, 2026 at 10:59 AM Rich Freeman via plug <plug@lists.phillylinux.org> wrote:
On 6/15/2026 2:03 PM, Rich Mingin (PLUG) via plug wrote:
> 1. If you are new to Arch, you should not have installed anything from
> the AUR. There is nothing in the AUR that you should need for basic
> functionality of your system.

Well, I'm not using Arch at the moment, but when I was using it, every
package I cared about was in AUR, and if they weren't there or in the
main repo I wouldn't have installed Arch in the first place.  Of course
I kept a close eye on them but there is only so much you can do to
detect attacks like these - they usually are subtle.

Some AUR helpers help to call out changes that you should pay attention
to and contrary to what seems to be popular belief I think a
well-designed AUR helper can make it more secure than installing things
manually.

Maybe things have improved but I think Arch does need to give
consideration to improving the security of the long tail.  There are
millions of FOSS programs out there, and most aren't going to be
packaged by a small core team.  People aren't installing things from AUR
because their primary goal is to get hacked.  They obviously want to use
some piece of software that wasn't in the main repo and they were
willing to jump through hoops to do it. Of course if a package does get
added to the main repo they should switch over, and this is another
thing an AUR helper could assist with.

I'm not sure AUR is a better model than a PPA or similar, as at least in
the latter case you're trusting things by source, and if the source
changes you need to intervene to get the updates.  I'm not as happy with
things like appimage unless there is some tool that actually keeps that
stuff up to date.

For me the thing that replaced AUR was k8s+flux+renovate. Obviously this
is a solution that isn't going to work for anybody who is focused more
on the desktop.

--
Rich

___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug