#malwarecheck — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malwarecheck, aggregated by home.social.
-
Also, notable mention. unexpected thread: https://github.com/lenucksi/aur-malware-check/issues/5
Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
Update: Looping in @archlinux here.
Also, any plans on enforcing this -> https://wiki.archlinux.org/title/DeveloperWiki:Building_in_a_clean_chroot for all the AUR build business?Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣
Edit: https://jguer.space/blog/2026-06-15-yay-v13 delivered. It's the #AURpocalypse 😱 🤣
#llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse
-
Forum FAQ explains how to check for compromised AUR packages after the Jun 9–12 supply‑chain attack — use paru -Qm or the provided scripts to detect 1,500+ backdoored packages; run the full scan and rotate credentials if infected. Read: https://discuss.cachyos.org/t/how-to-check-for-compromised-packages-from-the-current-aur-malware-attack/31077 🔒⚠️💻 #AUR #CachyOS #infosec #Arch #ArchBtw #MalwareCheck
tl;dr:
git clone https://github.com/lenucksi/aur-malware-check.git && cd aur-malware-check && sudo ./aur_check-v2.sh --full This performs install-date checks and rootkit/persistence heuristics.
-
git clone https://github.com/lenucksi/aur-malware-check.git && cd aur-malware-check && sudo ./aur_check-v2.sh --full This performs install-date checks and rootkit/persistence heuristics.