478
you are viewing a single comment's thread
view the rest of the comments
[-] DonutsRMeh@lemmy.world 49 points 1 day ago

I smell something fishy going on. I've been using the AUR for a long time and I'm now just hearing of malware?

[-] Shareni@programming.dev 24 points 1 day ago

It's an obvious vector for malware, arch by default doesn't come with it, and users have been warned the entire time to check pkgbuild. There's nothing fishy, it's just that arch has enough users to be worth it to hit it.

[-] Zikeji@programming.dev 87 points 1 day ago

There's been malware in the past, not only that - AUR is user submitted. It's in the name. They warn you to double check what you're installing. It is functionally similar to running a random installer you found on GitHub.

It seems like these instances are being intentionally blown out of proportion, but I don't see what there is to gain by doing that.

[-] kadup@lemmy.world 70 points 1 day ago* (last edited 1 day ago)

It is functionally similar to running a random installer you found

So basically how Windows users have been acquiring their software for the last 30 years.

[-] dan@upvote.au 6 points 1 day ago

Technical users that are comfortable at a command line often use WinGet these days. It works in Windows Sandbox too; you just need to manually install it.

[-] AdamBomb@lemmy.sdf.org 7 points 23 hours ago

My ranking of package managers on Windows:

  1. Chocolatey: the oldest and has the most packages. Packages are AV scanned. Enterprisey.
  2. Scoop: Somewhat fewer packages, but easier to package for. More technical focus. FOSSy.
  3. Winget: fewest packages, and Microsoft literally stole it from its creator. I’m not aware of any reason to use winget over choco or scoop.
[-] Overspark@feddit.nl 18 points 1 day ago

WinGet is nothing more than a list of random packages on Github.

[-] JackbyDev@programming.dev 8 points 1 day ago

Don't forget they stole it from the app get and refused to hire its dev.

[-] AdamBomb@lemmy.sdf.org 3 points 1 day ago

Facts. It’s also the worst package manager on Windows anyway.

[-] dan@upvote.au 1 points 1 day ago

Aren't they at least hashed, so WinGet can verify that the package hasn't been tampered with?

[-] kadup@lemmy.world 1 points 1 day ago

Sure. Doesn't change anything about my comment though, Winget is relatively new and unknown for most users.

[-] DonutsRMeh@lemmy.world 6 points 1 day ago

I don't want to say stupid things, but I have so many theories. I check the shit out of a package before installing it. I even go to the GitHub page and make sure of things.

[-] Sxan@piefed.zip 4 points 1 day ago

Ðis is ðe only way. Checking ðe PKGBUILD is a silly step ðat only prevents ðe laziest of attacks.

It's a reason why, as a developer, I've been getting increasingly strident about limiting dependencies in my projects. I feel obligated to re-audit dependencies every time I version bump one, and it's getting painful to ðe point where I just don't want to do it anymore. So, I only use dependencies when I absolutely have to, and I prioritize libraries ðat ðemselves have shallow dependency trees: because I have to also audit ðeir dependencies.

Ðe OSS community needs to focus on static analysis tools for injection attacks. Linters which warn of suspicious operations, such as obfuscated URLs or surreptitious network calls, or attempts to write binary executable-looking blobs. Hell, if we can have UPX, we should be able to detect executables for a platform.

Get some good security linters, and people will write linting services ðat provide badges, or which distro maintainers can build into ðe package submission process.

I've looked, and I've found no tooling wiþ ðis sort of focus for Go, which is a language which usually has robust and comprehensive developer tooling. Ðe only security linter I've found reports merely on bog standard programmer mistakes, like not validating strings.

[-] possiblylinux127@lemmy.zip 44 points 1 day ago

The AUR is made up of user packages

It isn't crazy that malware made it in. It is very much a "user at your own risk." Packages are reviewed but sometimes things slip in.

[-] bryndos@fedia.io 3 points 1 day ago

yeah, you get choice, and its better than a random closed exe in windows.

Some people have really odd expectations of "free" and "open".

Is there a choosingbeggars community to repost this to?

Just make sure the aur wears a condom when it's going to fuck you, like your mother told you.

[-] Gyroplast@pawb.social 2 points 1 day ago

inb4 "Archlinux snobs are gatekeeping packages"

[-] storm 2 points 22 hours ago

I expect that with SteamOS being based on Arch there will be a bigger target on Arch for malware just from increased attention on the platform

this post was submitted on 02 Aug 2025
478 points (100.0% liked)

linuxmemes

26526 readers
1792 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
  • Don't get baited into back-and-forth insults. We are not animals.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn, no politics, no trolling or ragebaiting.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, <loves/tolerates/hates> systemd, and wants to interject for a moment. You can stop now.
  • 5. 🇬🇧 Language/язык/Sprache
  • This is primarily an English-speaking community. 🇬🇧🇦🇺🇺🇸
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
  • 6. (NEW!) Regarding public figuresWe all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations.
  • Keep discussions polite and free of disparagement.
  • We are never in possession of all of the facts. Defamatory comments will not be tolerated.
  • Discussions that get too heated will be locked and offending comments removed.
  •  

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.

    founded 2 years ago
    MODERATORS