Arch Linux users just got another nasty malware: once again, AUR is powerful, but it is not a normal app store.
• Another wave of AUR malware was reported
• This comes after the previous incident involving 1,500 affected packages
• Newer malware was reportedly more sophisticated
• Obfuscated code was used to hide what it was doing
• Affected packages included Node.js packages, Plasma 6 applets, Firefox-related packages, LibreWolf extensions, Aura browser, and a NeoVim plugin
• One later report found more malware using a local Gemma E2B AI model
• This is about the AUR, not the official Arch repos
• Users should review PKGBUILDs and stop blindly installing community packages
This is why I love Arch, but also why I would never tell beginners to just spam yes through the AUR.
The AUR is amazing because you can find almost anything, but that freedom comes with risk. You are trusting community build scripts on your machine.
At this point, Arch may need stronger safeguards, or at least a temporary freeze when waves like this happen.