Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Halted

21 days ago by Karna to c/linux

Dirk 29 points 21 days ago

Adoptions are a mistake anyways. Remove unmaintained packages and block the name for several months.

path: 0 25056872, hotness: undefined, score: 29, children: 19
thingsiplay 43 points 21 days ago

Adoption of unmaintained packages to maintain them is not a mistake. The problem is the current implementation, not the idea behind it. It's like saying the AUR is a mistake, because some people do malicious stuff.

They should find a better solution, like adoption shouldn't be granted to everyone without question, especially new accounts who didn't maintain anything before. Mass adoption shouldn't be granted automatically (limit rate), in example 1 package adoption per day and if someone wants more, admins or moderators need to approve. And updates of newly adopted packages should wait a day.

Also the AUR helpers should do a better job. Always ask if a new adopted package should be updated and give a warning the maintainer changed.

path: 0 25056872 25057327, hotness: undefined, score: 43, children: 13
Dirk 12 points 21 days ago

The problem is the current implementation

Yes, exactly this! I am not surprised it happens. I’m surprised it didn’t happen before.

especially new accounts

Weren’t there “sleeper accounts” registered years ago that became active in the current wave?

Also the AUR helpers should do a better job.

Even experienced people will just update as if nothing could happen. Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.

path: 0 25056872 25057327 25058577, hotness: undefined, score: 12, children: 3
thingsiplay 5 points 21 days ago

Weren’t there “sleeper accounts” registered years ago that became active in the current wave?

Which does not invalidate my point about new accounts, but yes. Its important for new accounts, so once a sleeper account is banned, its not that easy to just create thousands of new accounts while everyone is focusing on the current active ones. And if, as I suggested, mass adoption per account is not possible, then the attacker has less to attack.

Edit: They need to make sure that sudden editing many packages in short time, with probably the same or similar lines should be automatically reported. They need some automated checks in place, at the very least. This would be a very suspicious behavior if many accounts are not active, and then suddenly all of them do something.

Even experienced people will just update as if nothing could happen.

Then you can't fault the system, if you are this reckless.

Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.

This would break all dependencies of this package. The point of adoption is to keep it working and stable. I'm highly against force changing the name, that is not a solution (at least not one I am happy about).

path: 0 25056872 25057327 25058577 25058720, hotness: undefined, score: 5, children: 2
Dirk 6 points 21 days ago

[Changing a package’s name] would break all dependencies of this package.

Yes, that is correct. But that should not be a big deal for packages that are actively maintained. The maintainer can simply change the dependency to the new name after making sure the new package is legit.

path: 0 25056872 25057327 25058577 25058720 25058985, hotness: undefined, score: 6, children: 1
trevor 7 points 21 days ago

Enforced commit signing and making it obvious when the signature changes would help make adoption much safer. I really hope they implement it.

path: 0 25056872 25057327 25058017, hotness: undefined, score: 7, children: 0
lemmyvore 0 points 21 days ago

They should find a better solution

Who's "they"? Because it's not Arch. Arch doesn't want to have anything to do with AUR, and neither does any of the Arch-derived distros. They're all perfectly happy taking advantage of it, of course, but not the responsibility.

path: 0 25056872 25057327 25061301, hotness: undefined, score: 0, children: 7
thingsiplay 9 points 20 days ago

Who’s “they”? Because it’s not Arch. Arch doesn’t want to have anything to do with AUR, and neither does any of the Arch-derived distros. They’re all perfectly happy taking advantage of it, of course, but not the responsibility.

Where did you got this nonsense from? What do you mean "they are not Arch"? The AUR is managed and operated by the Archlinux team. As the packages are community-driven content, they cannot guarantee and give support, because it is not their package. But they are still managing and supporting the AUR itself.

path: 0 25056872 25057327 25061301 25061561, hotness: undefined, score: 9, children: 6
iusemybrain 1 point 16 days ago

it's not managing, as you seem to imply, it's just hosting.

Arch hosts the AUR repository, the maintenance of the packages is on the developers who developed the package.

If someone sneaks in spyware or malware inside the makepkg, that isn't arch's fault, that's the maintainers fault of the makepkg.

path: 0 25056872 25057327 25061301 25061561 25136464, hotness: undefined, score: 1, children: 1
lemmyvore -8 points 20 days ago

And you're gonna see the Arch team wash their hands of the whole thing, like they did in the past whenever the AUR was in trouble.

That's not real ownership.

path: 0 25056872 25057327 25061301 25061561 25061767, hotness: undefined, score: -8, children: 3
lemmyvore 13 points 21 days ago

Remove unmaintained packages and block the name for several months.

Alright, but that would mean most of AUR. Have a look at the package statistics box on the AUR homepage. Most packages fall under that definition in one way or another. The vast majority of the AUR is package some random person added once then never bothered with ever again.

Frankly I'm surprised that the AUR has survived for so long in its current form, for what is basically a shell script distribution system with zero supervision and zero safety guards.

path: 0 25056872 25061280, hotness: undefined, score: 13, children: 3
Dirk 3 points 21 days ago path: 0 25056872 25061280 25061383, hotness: undefined, score: 3, children: 2
lemmyvore 2 points 21 days ago

The orphan package criteria is misleading. If you look at the infobox you'll see that there are only 69 package "maintainers" for 100k+ packages.

path: 0 25056872 25061280 25061383 25061459, hotness: undefined, score: 2, children: 1
Dirk 2 points 20 days ago

THIS is misleading, though.

There are definitely more than just 69 users who uploaded packages to the AUR.

path: 0 25056872 25061280 25061383 25061459 25061534, hotness: undefined, score: 2, children: 0
chortle_tortle 1 point 18 days ago

From the mailing list thread:

For the record, those are all new packages (not orphaned packages being adopted). I assume more will come, we'll clean those as soon as possible.

In the mean time stay vigilant, probably refrain from installing freshly pushed new packages from the AUR for now.

So wasn't adoption in this case. Looks like instead they submitted a bunch of git/bin versions of existing packages.

path: 0 25056872 25105833, hotness: undefined, score: 1, children: 0
SocialistVibes01 13 points 20 days ago

I use malware, btw 😎

Arch should be stopped to be recommended to new users of Linux ASAP

path: 0 25070199, hotness: undefined, score: 13, children: 12
JamesBoeing737MAX 17 points 20 days ago

Well, just don't use AUR for everything. They don't even recommend helpers. It's ment to be tedious, to discourage usage for non-necesarry bullshit.

path: 0 25070199 25070835, hotness: undefined, score: 17, children: 0
peetabix 8 points 20 days ago

Is anybody really recommending Arch to new users though?

path: 0 25070199 25070827, hotness: undefined, score: 8, children: 6
bleustenns 10 points 20 days ago

Yeah, there's a ton of people that recommend Cachy when it is really meant for tinkerers IMHO

path: 0 25070199 25070827 25071255, hotness: undefined, score: 10, children: 4
peetabix 1 point 20 days ago

I suppose so. I run Cachy now but that's only after 3 years of switching distros several times and getting more confident with how Linux works.

path: 0 25070199 25070827 25071255 25071295, hotness: undefined, score: 1, children: 0
LordKitsuna 0 points 19 days ago

I'm very tired of the rhetoric that Arch is only meant for tinkerers. If all you do is have plasma steam and a web browser it's no more or less likely to break than any other distro. You could go your entire life without ever looking at the terminal.

And while yes this malware is a problem it is specifically in the aur, the arch user repository an unofficial repository not officially supported, just don't use it. Unless you need a weird piece of software generally related to some type of specific hobby you're unlikely to ever even want to look at it anyway.

path: 0 25070199 25070827 25071255 25084436, hotness: undefined, score: 0, children: 2
bleustenns 1 point 18 days ago

I do agree with this in theory. I just don't know many 'normal people' that are going to only ever require those three things. (Totally with you on the AUR bit)

path: 0 25070199 25070827 25071255 25084436 25099212, hotness: undefined, score: 1, children: 1
SocialistVibes01 1 point 20 days ago

They have been as of late

path: 0 25070199 25070827 25074791, hotness: undefined, score: 1, children: 0
kylian0087 2 points 18 days ago

Arch as far as I am aware has never been recommended to new users. Sure their is CachyOS and other variants. And on top of that AUR you shut read the build scripts. But I suppose not many people do that unfortunately.

path: 0 25070199 25100270, hotness: undefined, score: 2, children: 2
SocialistVibes01 1 point 18 days ago

It's a trend between kids going for an "advanced" distro

path: 0 25070199 25100270 25105095, hotness: undefined, score: 1, children: 0
iusemybrain 1 point 16 days ago

more importantly, they don't recommend that users use the AUR repository (that isn't to say they are opposed to it). Some advice they have given is to review what the dependencies are before executing the package with an AUR helper or manually.

Just to make a point, there is a surplus of these non officially supported (from OS developers) repositories, such as the terra repository for fedora. It has the same vulnerability as AUR, and yet that is targeted for new users.

Much like how fedora doesn't officially support Terra, arch doesn't support AUR. There is a reason why it's called AUR (arch user repository) over ASR (arch supported repository). AUR entails that it is not supported by arch.

path: 0 25070199 25100270 25136042, hotness: undefined, score: 1, children: 0
Sanctus 0 points 18 days ago

You have to go download an AUR helper to even get into the AUR, it does not come by default on Arch systems. You have to actually do this to yourself to get the malware.

path: 0 25070199 25093301, hotness: undefined, score: 0, children: 0
LiveLM 8 points 20 days ago

Why tf didn't they leave it disabled since the last attack?

path: 0 25063598, hotness: undefined, score: 8, children: 0
Admetus 8 points 21 days ago

Just saw DeepSeek TUI in there, that's probably going to be a whopper that hit quite a few users.

path: 0 25057529, hotness: undefined, score: 8, children: 2
thingsiplay 10 points 21 days ago

You mean https://aur.archlinux.org/... from the list https://lists.archlinux.org/... ? It has 0 votes and Popularity is at 0.000000, since it was uploaded 2 months ago. And there is a non Git version that is not listed (probably not affected) at https://aur.archlinux.org/packages/deepseek-tui . On top of it, on their website https://deepseek-tui.org/#install the main recommended way to install it is with npm and there is even a way to build it with Rust it seems (I'm a bit unsure).

So I don't think it hit that many users, as only a couple of people since Mai would want to install it, and they have to have updated it to build from source in recent days. That is a very narrow number of people, just by my gut feeling.

path: 0 25057529 25057780, hotness: undefined, score: 10, children: 1
bleustenns 2 points 20 days ago

Thank you for verifying!!

path: 0 25057529 25057780 25071398, hotness: undefined, score: 2, children: 0
eremophila 6 points 20 days ago

friends don't let friends use the AUR

path: 0 25063542, hotness: undefined, score: 6, children: 9
alsimoneau 2 points 20 days ago

What's the alternative?

path: 0 25063542 25069209, hotness: undefined, score: 2, children: 6
eremophila 6 points 20 days ago

I only use official and flatpak, I wouldn't even use flatpak if official had more.

Chaotic aur might be worth looking into if aur is what you want. Everything there is theoretically checked.

path: 0 25063542 25069209 25069431, hotness: undefined, score: 6, children: 2
JC1 1 point 20 days ago

Are you sure about chaotic? I removed it as I thought it wasn't really checked as I read in a comment here.

path: 0 25063542 25069209 25069431 25070465, hotness: undefined, score: 1, children: 1
eremophila 1 point 19 days ago

might be worth looking into

I'm not sure of anything, I would look into it further were I planning on using it, which I might do in the future, Garuda KDE lite looks like a decent distro.

From the little I have looked into it, it is all meant to be checked, adding an extra layer of protection, as long as your trust the people behind it (much like official I guess)

path: 0 25063542 25069209 25069431 25070465 25078880, hotness: undefined, score: 1, children: 0
Nilz 4 points 20 days ago path: 0 25063542 25069209 25069311, hotness: undefined, score: 4, children: 0
perfectly_boiled_pizza 1 point 16 days ago

😎 Debian 😎

path: 0 25063542 25069209 25126416, hotness: undefined, score: 1, children: 1
alsimoneau 1 point 16 days ago

Not rolling release

path: 0 25063542 25069209 25126416 25131439, hotness: undefined, score: 1, children: 0
kahoodd -6 points 20 days ago

all they have to do is to check the damn diff, if that's not easy for someone then they should stop using a computer altogether. I mean they could just click to random links on the internet right?

path: 0 25063542 25070772, hotness: undefined, score: -6, children: 1
Axolotl_cpp 2 points 19 days ago

, if that's not easy for someone then they should stop using a computer altogether

No. It just means they should stop using AUR

path: 0 25063542 25070772 25084402, hotness: undefined, score: 2, children: 0
Asonyxi 5 points 19 days ago

Man I feel like I dodged a bullet switching to Fedora right before this AUR fuckery started to happen...

path: 0 25081890, hotness: undefined, score: 5, children: 5
motruck 11 points 19 days ago

You don't have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora's Copr.

path: 0 25081890 25083907, hotness: undefined, score: 11, children: 3
chortle_tortle 1 point 18 days ago

Sure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.

path: 0 25081890 25083907 25105220, hotness: undefined, score: 1, children: 0
Scrollone 1 point 19 days ago

I wonder if Ubuntu PPAs are also compromised

path: 0 25081890 25083907 25084067, hotness: undefined, score: 1, children: 1
motruck 2 points 19 days ago

The chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.

path: 0 25081890 25083907 25084067 25086804, hotness: undefined, score: 2, children: 0
darkstar 1 point 14 days ago

Same. I was on Cachy for a few months but recently switched back to Fedora. I'm sleeping very peacefully.

path: 0 25081890 25171272, hotness: undefined, score: 1, children: 0
daggermoon 4 points 20 days ago

Do I really need to audit my system again?

path: 0 25068777, hotness: undefined, score: 4, children: 1
tekdeb 11 points 20 days ago

Not if you follow the normal safety precautions for using the AUR. There are several things you can do to look for red flags, but the most essential thing is to read the PKGBUILDs. And helpers like yay, paru and Shelly can all show diffs which makes that much easier after the initial installation because in most cases you'll just see that the version and checksum has changed which means it's as trustworthy as last time.

This has always been the case, and will continue to be the case unless the Arch team restricts the AUR which quickly can make it lose exactly what makes it so good.

path: 0 25068777 25069750, hotness: undefined, score: 11, children: 0
Vendetta9076 3 points 18 days ago

I feel like when this pops up everyone freaks out and yells about how it's proof the aur sucks and arch is doomed. Do you people randomly install GitHub repos without any due diligence? Do you click on random ads to download bake bean can cursors? There's malware fuckin everywhere. Just do your due diligence and don't get screwed. And if you do get malware, have a plan to make it irrelevant. Anyone who doesn't do these things should in no way be using the AUR.

path: 0 25093254, hotness: undefined, score: 3, children: 0
ShinkanTrain -14 points 21 days ago

No way to prevent this, says only repo where this regularly happens

path: 0 25057629, hotness: undefined, score: -14, children: 6
Eggymatrix 3 points 20 days ago

I mean, nobody is saying there is no way to prevent this, and I would hardly say that "twice" can be cathegorized as regularly.

Also I find this of extremely bad taste as you seem to compare this to school shootings, with literal children deaths. I would say that a few thinkerers getting pwned from their claude tokens is a couple orders of magnitude less serious.

path: 0 25057629 25072250, hotness: undefined, score: 3, children: 0
thingsiplay 3 points 21 days ago

Besides all the other non infected ways to install the software, there is a way to prevent this: Just read the AUR package before install and don't trust blindly any new maintainer.

path: 0 25057629 25057815, hotness: undefined, score: 3, children: 1
Faux 7 points 21 days ago

It's metaphysical approach to security. Enshrined rules that can't be enforced don't define user's behavior.

path: 0 25057629 25057815 25058231, hotness: undefined, score: 7, children: 0
BradleyUffner 1 point 21 days ago

Isn't this similar to the reason a lot of people hate snaps? Or am I misunderstanding something? I'm not an Arch user (btw) so I'm not super familiar with AUR.

path: 0 25057629 25060709, hotness: undefined, score: 1, children: 2
throwaway403 7 points 21 days ago path: 0 25057629 25060709 25061304, hotness: undefined, score: 7, children: 0
mnemonicmonkeys 2 points 20 days ago

Some of the hate for snaps is because it's Cannonical trying to use its install base (Ubuntu) to push a particular format on the entire community as a vector for control

path: 0 25057629 25060709 25070549, hotness: undefined, score: 2, children: 0
linux
linux

@lemmy.ml

login for more options
67095
9208
4286

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

go to feed...