On the 16th of July, at around 8pm UTC+2, a malicious AUR package was uploaded to the AUR. Two other malicious packages were uploaded by the same user a few hours later. These packages were installing a script coming from the same GitHub repository that was identified as a Remote Access Trojan (RAT).

The affected malicious packages are:

  • librewolf-fix-bin
  • firefox-patch-bin
  • zen-browser-patched-bin

The Arch Linux team addressed the issue as soon as they became aware of the situation. As of today, 18th of July, at around 6pm UTC+2, the offending packages have been deleted from the AUR.

We strongly encourage users that may have installed one of these packages to remove them from their system and to take the necessary measures in order to ensure they were not compromised.

Follow up

There are more packages with this malware found.

  • minecraft-cracked
  • ttf-ms-fonts-all
  • vesktop-bin-patched
  • ttf-all-ms-fonts

What to do

If you installed any of these packages, check your running processes for one named systemd-initd (this is the RAT).

The suspicious packages have a patch from this now-inaccessible Codeberg repo: https://codeberg.org/arch_lover3/browser-patch

The Arch maintainers have been informed of all this already and are investigating.

    • Absolutely.

      The Arch User Repository is a way for anyone to easily distribite software.

      Hence it has never been secure, and rather than claim it is, you mostly see people and documentation warn you about this, and to be careful if using it.

      Any schmuck can make whatever they want available via the AUR. That’s how even the tiniest niche project can often be installed via the AUR. But you trade in some security for that convenience.

      • It shouldn’t be used as a marketplace, it should be used as a repository. You can probably find a lot of malware on GitHub, doesn’t mean you go there to choose your text editor.

        I never search the AUR directly, I only use it if some README tells me I can install their software via an AUR package.

        • Dima ( Dima@feddit.uk ) 
          link
          fedilink
          arrow-up
          10
          ·
          1 year ago

          Yeah, I search the AUR not to discover packages, but to see if something I want to install is in there, if it is I check the PKGBUILD and make sure none of the sources/commands/patches are suspicious.
          People need to remember it’s not some carefully vetted app store and that they need to be the ones vetting any packages they install and any changes when updating.

  • minecraft-cracked

    Gotta assume that if any Arch users actually fell for that one, that they either let their kids use their device or they’re generally not smart ( which absolutely goes against my stereotypical view of an arch user ).

    • pfr ( pfr@lemmy.sdf.org ) 
      link
      fedilink
      arrow-up
      5
      ·
      1 year ago

      The stereotype of arch uses generally being smart is no longer. The “I use arch btw” meme brought a whole new user base to arch. You’ll find them on r/unixporn showing off their hyperland rice that they copied from some other user…

      • moseschrute ( moseschrute@lemmy.ml ) 
        link
        fedilink
        English
        arrow-up
        8
        ·
        1 year ago

        I had no idea that existed but I’ve just returned from r/unixporn. There are some sick setups. Also we all copy. My entire neovim config is copied and modified from a couple dozen setups I admired. Nothing wrong with copying things you like. Don’t gate keep Linux.

        However… Minecraft cracked is pretty funny lol.

        • lattrommi ( lattrommi@lemmy.ml ) 
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 year ago

          I agree that gatekeeping is no good and people should not do that.

          However…

          we all copy

          I do not feel that assuming all people copy, should be done either, in my opinion.

            • lattrommi ( lattrommi@lemmy.ml ) 
              link
              fedilink
              English
              arrow-up
              2
              ·
              1 year ago

              I don’t know if there is a word for what I was trying to point out.

              Like an opposite to gatekeeping, sort of.

              I do not like when people use ‘we’, in ways that include people that it does not apply to. Lumping everyone together inaccurately into a group.

    • Voytrekk ( voytrekk@sopuli.xyz ) 
      link
      fedilink
      English
      arrow-up
      18
      ·
      1 year ago

      The arch maintainers package more software than most other distributions. Some items they leave in the AUR by choice, if the Dev prefers it there. The key is to use the AUR sparingly and only if you trust the packager.

      • pyssla ( pyssla@quokk.au ) 
        link
        fedilink
        English
        arrow-up
        7
        ·
        1 year ago

        The arch maintainers package more software than most other distributions.

        Sorry, but I fail to see this.

        I suppose if you’re accounting literally all independent distros, then you’re probably right. However, if we’d be more realistic and compare it to other well-established independent distros[1], then we notice that the vastness of the packages found in Arch’s repository is rather lackluster at the very least. Heck, by virtually all metrics, Arch together with its derivatives undoubtedly belong in the upper echelons of usage stats; only being second to the Debian-family of distros. IMO, however, the size of its repository absolutely doesn’t reflect this; as it’s only bigger than Slackware, Solus and Void. The inclusion of these smaller projects is arguably charitable on my side*. But to drive the point home very clearly: Arch’s repository is smaller than Alpine’s, Debian’s, Fedora’s, openSUSE’s and Gentoo’s with a ratio of (about) two to one (except for openSUSE).


        1. I’m basically counting Alpine, Debian, Fedora, Gentoo, openSUSE, Slackware, Solus and Void. I didn’t count Guix System and NixOS for how their ‘repositories’ are built different and therefore not easily comparable to the others. ↩︎

        • Voytrekk ( voytrekk@sopuli.xyz ) 
          link
          fedilink
          English
          arrow-up
          10
          ·
          1 year ago

          I don’t know if raw package counts is the best comparison. Unlike say Fedora, Arch bundles everything related to a project in the same file. If you want Qt6-base on Arch, that is one package. If you want it on Fedora, it is going to have a lib, header, docs, and maybe a few other packages.

          Just from personal experience, I do not have issues with finding packages in the main repos, with only a handful of my packages coming from the AUR. This is not the case with others, like Fedora where extra repos need to be added, like EPEL and RPM Fusion.

          • pyssla ( pyssla@quokk.au ) 
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 year ago

            Thank you for the quick response!

            I don’t know if raw package counts is the best comparison.

            You’re probably right. Do you think we got anything better to go by?

            Unlike say Fedora, Arch bundles everything related to a project in the same file. If you want Qt6-base on Arch, that is one package. If you want it on Fedora, it is going to have a lib, header, docs, and maybe a few other packages.

            Can’t comment on this. Though, the list of packages with qt6 in their name is considerably longer in Fedora. However, I wonder if this simply reflects that Fedora, by virtue of having a larger repository, also has more stuff related to qt6. Or, as you posited it, chooses to package the same content over multiple packages instead of bundling them like it’s supposedly happening on Arch.

            Just from personal experience, I do not have issues with finding packages in the main repos, with only a handful of my packages coming from the AUR. This is not the case with others, like Fedora where extra repos need to be added, like EPEL and RPM Fusion.

            Hmm…, I feel you might be conflating stuff. Please allow me to elaborate on what I mean.

            Fedora is not able to include some packages in its own repository due to legal reasons. As such, these are relayed to RPM Fusion instead. Which means that a well-functioning Fedora installation (almost necessarily) desires to install some packages from RPM Fusion. So, RPM Fusion exists as a ‘hack’ of sorts to protect Fedora from legal charges and NOT because they’re too lazy (or something) to ship those packages themselves. To be clear, RPM Fusion is accepted as a trusted third-party repository.

            Arch, on the other hand, is rather lenient on what they can include in their repositories. Basically enabling them to package within their repositories all codecs and whatnot without them being visibly worried about the legal consequences of this ordeal.

            To be honest, I don’t know exactly where this discrepancy comes from. But I wouldn’t be surprised if it’s related to how Arch is basically a genuine community distro while Fedora has official ties to Red Hat.

            Btw, small correction, AFAIK you’re not supposed to install packages from the EPEL on Fedora. Perhaps you meant COPR (basically Fedora’s AUR) or Terra instead?

  • Ulrich ( Ulrich@feddit.org ) 
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 year ago

    The affected malicious packages are:

    librewolf-fix-bin firefox-patch-bin zen-browser-patched-bin

    So…did someone just like create a new package cloning these or did they somehow get into the “official” repository? Is there no attestation process?