• thingsiplay ( thingsiplay@lemmy.ml ) 
    link
    fedilink
    arrow-up
    42
    ·
    edit-2
    4 months ago

    As an user of the AUR, this is devastating news to me. I am also guilty of accepting updates without reading the latest changes, even if yay asks me if I want to. This is a reminder to everyone to only install from the AUR for absolutely necessary stuff only, and only if you trust the maintainer. And to at least have a look if something suspicious is going in with the recent changes in the package recipe. AND to read in the communities and news.

    I don’t understand why there still no official announcement as a warning from the Archlinux team at https://archlinux.org/news/ . Is there a different place for security news specifically about the AUR to subscribe to? EDIT: https://archlinux.org/news/active-aur-malicious-packages-incident/ They did it, an official message.

    • trevor (any/all)  ( trevor@lemmy.blahaj.zone ) 
      link
      fedilink
      English
      arrow-up
      29
      ·
      edit-2
      4 months ago

      The fact that the Arch maintainers seem to prefer Reddit over their own fucking news channel is what made me switch from Arch years ago. I got sick of upstream breaking changes fucking my system because they wouldn’t notify people through official channels, only to find it later on /r/archlinux 🙄🙄🙄

    • araneae ( araneae@beehaw.org ) 
      link
      fedilink
      arrow-up
      6
      ·
      4 months ago

      This is a reminder to everyone to only install from the AUR for absolutely necessary stuff only, and only if you trust the maintainer.

      Unfortunately not foolproof either. I have no infected packages that I know of because I happen to be on a new install, but I caught wind of the LAST AUR botnet infiltration and switched to flatpaks or source builds. Since then I drifted back to AUR for convenience. I thought I was being clever only using AUR packages when I could be “sure” the author of the original software package pushed to AUR, and this was easy since devs who build on Arch typically recommend AUR whether they maintain the package or not. Today I found out spoofing package ownership is apparently easy and so is spoofing git credentials.

      I was on Endeavour and it was incredible, but I’m not That Power User and I feel like part of the problem. The worst part of all of this is its owing to an influx of users who want the same ease of use they used to enjoy, but in Windows SOP is installing whatever the fuck you want on Internet Explorer and bugging your sysadmin to fix whatever happens. Its probably really hard to be any kind of FOSS developer right now.

      • Yes, definitely not foolproof. This is more of a wake up call to be at least careful and reconsider every single AUR package one has installed. For me, I was lucky too. But in my case it wasn’t pure luck that the few AUR packages I have installed aren’t affected. See, because since years using the AUR (sparingly! including my own package :D ) I always feared off orphaned packages and removed them as soon as I could. This incident here is proof I was right.

        For some stuff I also prefer the Flatpak, because I do not trust everyone on the AUR, as they operate on root rights! When I brought this up on Endeavor, they disliked my opinion (as a fresh user) and the trusted community members there explained to me that the AUR is way more safe than Flatpak, because there is a trust system of upvotes and everyone can flag the packages, and that Flatpak has a wrong sense of security. That is what they told me and totally ignored my issues with AUR… one of the reasons why I do not visit the EndeavourOS community… I digress…

  • James ( James@lemmy.ca ) 
    link
    fedilink
    arrow-up
    10
    ·
    4 months ago

    The AUR is basically just a shortcut for downloading random shit off GitHub.

    It gives un-experienced users a false sense of security.

    • softotteep ( solxix@pawb.social ) 
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      The false sense of security is actually caused by people saying the AUR is the easiest way to safely get all your packages, when in reality the AUR itself tells you to always review PKGBUILDs and to not blindly trust AUR packages.

  • starblursd ( starblursd@lemmy.zip ) 
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    4 months ago

    There were announcements and security ping in the arch Linux community discord… But I wish they’d be more vocal on this outside discord especially given discords controversy as of late

    Update: they finally posted about it in the arch news feed last night… A bit late but better than never. Npm removed the malicious package, but then the bad actors started using bun instead…

    As others have proposed, I really think that orphaned packages should require a moderator of the aur to approve the commit and acquisition of an orphaned package. Currently nothing stops someone from spinning up accounts and hijacking these abandoned projects

  • Whelp…I’ve REALLY loved EndeavourOS for my laptop, especially because I felt I could mess around with stuff, but maybe this is my call to use something like Fedora or a OpenSUSE variant (I love Tumbleweed dearly).

    Nothing against the incredible Arch, but I’m deffos that user who does

    > yay 
    > "Build files exist. Do clean build? N"  
    > "View changes? N".
    

    ENTER.

    I want to learn, but also I’m a bit of a danger to myself if this malware threat is this broad.

    • Alavi ( somegeek@programming.dev ) 
      link
      fedilink
      arrow-up
      4
      ·
      4 months ago

      Have you heard about the recent fuckups of fedora? fedora is a shitshow.

      If you just yolo with yay anyway, you will get compromised on any system you use, ni matter the OS or distro, my dude.

      • Have you heard about the recent fuckups of fedora? fedora is a shitshow.

        Oh really? I guess I haven’t. 😬

        Yeah it was late here so I think I was poorly mushing two separate thoughts together there. I meant I was thinking of moving to a distro that isn’t as bleeding-edge for the laptop I’m not updating every single day…But also I should find something that still has a nice large software variety so I stay off AUR.

        OpenSUSE has the “Open Build System” which I’ve used for like one package. So that’s pretty neat.

        This is really tough because I have two gamers in the family using Nvidia cards I want to help move off of Windows, but I don’t want them running into having to roll back as often as I have or fiddle too much, but I feel like Mint is a little too far behind.

        So I was considering the KDE spin of Fedora for them…But yeah, the answer isn’t so easy anymore lol.

  • Aatube ( Aatube@kbin.melroy.org ) 
    link
    fedilink
    arrow-up
    4
    ·
    4 months ago

    (hopefully this doesn’t read as blaming the victims instead of the attackers but) I personally don’t think it’s that complicated to read the updates to AUR packages. It’s not any more hard than only commenting after reading the links that people post here instead of just the headlines—which we all do, right?

  • Helix 🧬 ( helix@feddit.org ) 
    link
    fedilink
    English
    arrow-up
    2
    ·
    4 months ago

    How do I check if a system has been affected most easily? As far as I have seen it’s related to the npm package atomic-lockfile, so would that be enough?

    npm ls atomic-lockfile