A new Maintainer adopted gnome-randr-rust and added an install file with the following: npm install atomic-lockfile yargs https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
This is almost certainly malicious. If randomly installing NPM wasn't enough of a smoking gun, the atomic-lockfile package on NPM was only uploaded yesterday and points to a GitHub user and repo that doesn't exist. On Thu, 11 Jun 2026, at 2:50 PM, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
On 6/11/26 3:50 PM, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
Thanks, the offending commit was da9f4cf2d470bd603968ef605736285a2e0c8880, I've rolled back the repository to the previous commit d6801693e68e13267e33bb34080b6fa7f057c850. Another moderator already suspended the user. The pattern is always the same, `npm install something` in post_install which in turn has a package.json with (the exact path varies): ``` [...] "scripts": { [...] "preinstall": "./src/hooks/deps", [...] }, [...] ``` Which is an ELF executable. I've also notified npmjs.com that atomic-lockfile is malware. Thanks for the report, very much appreciated. kpcyrd
On Thu, Jun 11, 2026 at 01:50:48PM +0000, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following: npm install atomic-lockfile yargs
more packages with malicious commits and same install function: - python-apt - python-cerealizer - python-orange - vim-pythonhelper accounts: - dafneprats - andremonnet - robertwalter - grecaarmellini Also please check packages maintained by those users.
This as well: https://aur.archlinux.org/cgit/aur.git/commit/?h=ledger-udev-bin&id=d60a201d... On Thu, 11 Jun 2026 at 22:34, a821 <a821@mail.de> wrote:
On Thu, Jun 11, 2026 at 01:50:48PM +0000, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following: npm install atomic-lockfile yargs
more packages with malicious commits and same install function:
- python-apt - python-cerealizer - python-orange - vim-pythonhelper
accounts:
- dafneprats - andremonnet - robertwalter - grecaarmellini
Also please check packages maintained by those users.
https://aur.archlinux.org/cgit/aur.git/commit/?h=electrum-nmc&id=9dee9b3f9a0... https://aur.archlinux.org/cgit/aur.git/commit/?h=python-affine&id=c7887204a2... https://aur.archlinux.org/cgit/aur.git/commit/?h=python-axolotl-git&id=2f0c6... Looks like there's a pattern of hijacking the exact same name as a previous maintainer. On Thu, 11 Jun 2026 at 22:38, Nicolas Boichat <nicolas@boichat.ch> wrote:
This as well: https://aur.archlinux.org/cgit/aur.git/commit/?h=ledger-udev-bin&id=d60a201d...
On Thu, 11 Jun 2026 at 22:34, a821 <a821@mail.de> wrote:
On Thu, Jun 11, 2026 at 01:50:48PM +0000, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following: npm install atomic-lockfile yargs
more packages with malicious commits and same install function:
- python-apt - python-cerealizer - python-orange - vim-pythonhelper
accounts:
- dafneprats - andremonnet - robertwalter - grecaarmellini
Also please check packages maintained by those users.
On 6/11/26 4:44 PM, Nicolas Boichat wrote:
https://aur.archlinux.org/cgit/aur.git/commit/?h=electrum- nmc&id=9dee9b3f9a0bd918c09d5ebb45f00e5270429d5e https://aur.archlinux.org/cgit/aur.git/commit/?h=python- affine&id=c7887204a2878aedd60dbe0523f9f4ee29096cf3 https://aur.archlinux.org/cgit/aur.git/commit/?h=python-axolotl- git&id=2f0c62bdd9f80ccc5c1ddbbeb9c57e97d644b9f3
Done, thanks
Wow, what a flood. Here's more: flashfocus: https://aur.archlinux.org/cgit/aur.git/commit/?h=flashfocus&id=7cd3dc436d1f9... efiboots-git: https://aur.archlinux.org/cgit/aur.git/commit/?h=efiboots-git&id=f01590d8753... python-privy-git: https://aur.archlinux.org/cgit/aur.git/commit/?h=python-privy-git&id=1a28a8e... meteo: https://aur.archlinux.org/cgit/aur.git/commit/?h=meteo&id=25051858b9a64dcc3a...
Hi, Also taken over: nextcloud-git nextcloud-app-integration-google nextcloud-app-repod nextcloud-app-facerecognition nextcloud-app-audioplayer nextcloud-app-twofactor-gateway Python-django-modelcluster Best regards
Am 11. Juni 2026 17:39:33 MESZ schrieb Lex Black <autumn-wind@web.de>:
Hi, Also taken over: nextcloud-git nextcloud-app-integration-google nextcloud-app-repod nextcloud-app-facerecognition nextcloud-app-audioplayer nextcloud-app-twofactor-gateway Python-django-modelcluster
Best regards
Oh, and nextcloud-app-gpoddersync And those were just the ones I got notifications for Best regards
Am 11. Juni 2026 17:48:18 MESZ schrieb Lex Black <autumn-wind@web.de>:
Am 11. Juni 2026 17:39:33 MESZ schrieb Lex Black <autumn-wind@web.de>:
Hi, Also taken over: nextcloud-git nextcloud-app-integration-google nextcloud-app-repod nextcloud-app-facerecognition nextcloud-app-audioplayer nextcloud-app-twofactor-gateway Python-django-modelcluster
Best regards
Oh, and nextcloud-app-gpoddersync
And those were just the ones I got notifications for
Best regards
And the next one python-django-rest-knox carmelobartolome https://aur.archlinux.org/pkgbase/python-django-rest-knox/
On 2026-06-11 17:52, Lex Black wrote:
Am 11. Juni 2026 17:48:18 MESZ schrieb Lex Black <autumn-wind@web.de>:
Am 11. Juni 2026 17:39:33 MESZ schrieb Lex Black <autumn-wind@web.de>:
Hi, Also taken over: nextcloud-git nextcloud-app-integration-google nextcloud-app-repod nextcloud-app-facerecognition nextcloud-app-audioplayer nextcloud-app-twofactor-gateway Python-django-modelcluster
Best regards
Oh, and nextcloud-app-gpoddersync
And those were just the ones I got notifications for
Best regards
And the next one python-django-rest-knox carmelobartolome https://aur.archlinux.org/pkgbase/python-django-rest-knox/
Done, thanks.
On Thu, Jun 11, 2026 at 6:52 PM Lex Black <autumn-wind@web.de> wrote:
Am 11. Juni 2026 17:48:18 MESZ schrieb Lex Black <autumn-wind@web.de>:
Am 11. Juni 2026 17:39:33 MESZ schrieb Lex Black <autumn-wind@web.de>:
Hi, Also taken over: nextcloud-git nextcloud-app-integration-google nextcloud-app-repod nextcloud-app-facerecognition nextcloud-app-audioplayer nextcloud-app-twofactor-gateway Python-django-modelcluster
Best regards
Oh, and nextcloud-app-gpoddersync
And those were just the ones I got notifications for
Best regards
And the next one python-django-rest-knox carmelobartolome https://aur.archlinux.org/pkgbase/python-django-rest-knox/
python-future, python-tradingeconomics, python-argdispatch, zing-8-bin and python-nipype are also affected (and a lot more too) Maybe we should emergency auto-reject all packages that add a npm dependency for now?
One more: https://aur.archlinux.org/cgit/aur.git/log/?h=python-rembg On Thu, 11 Jun 2026 at 18:12, DodoGTA GT <aidas957@gmail.com> wrote:
On Thu, Jun 11, 2026 at 6:52 PM Lex Black <autumn-wind@web.de> wrote:
Am 11. Juni 2026 17:48:18 MESZ schrieb Lex Black <autumn-wind@web.de>:
Am 11. Juni 2026 17:39:33 MESZ schrieb Lex Black <autumn-wind@web.de>:
Hi, Also taken over: nextcloud-git nextcloud-app-integration-google nextcloud-app-repod nextcloud-app-facerecognition nextcloud-app-audioplayer nextcloud-app-twofactor-gateway Python-django-modelcluster
Best regards
Oh, and nextcloud-app-gpoddersync
And those were just the ones I got notifications for
Best regards
And the next one python-django-rest-knox carmelobartolome https://aur.archlinux.org/pkgbase/python-django-rest-knox/
python-future, python-tradingeconomics, python-argdispatch, zing-8-bin and python-nipype are also affected (and a lot more too)
Maybe we should emergency auto-reject all packages that add a npm dependency for now?
On 2026-06-11 18:13, Matthias Kurz wrote:
One more: https://aur.archlinux.org/cgit/aur.git/log/?h=python-rembg <https://aur.archlinux.org/cgit/aur.git/log/?h=python-rembg>
On Thu, 11 Jun 2026 at 18:12, DodoGTA GT <aidas957@gmail.com <mailto:aidas957@gmail.com>> wrote:
On Thu, Jun 11, 2026 at 6:52 PM Lex Black <autumn-wind@web.de <mailto:autumn-wind@web.de>> wrote: > > Am 11. Juni 2026 17:48:18 MESZ schrieb Lex Black <autumn- wind@web.de <mailto:autumn-wind@web.de>>: > >Am 11. Juni 2026 17:39:33 MESZ schrieb Lex Black <autumn- wind@web.de <mailto:autumn-wind@web.de>>: > >>Hi, > >>Also taken over: > >>nextcloud-git > >>nextcloud-app-integration-google > >>nextcloud-app-repod > >>nextcloud-app-facerecognition > >>nextcloud-app-audioplayer > >>nextcloud-app-twofactor-gateway > >>Python-django-modelcluster > >> > >>Best regards > > > >Oh, and > >nextcloud-app-gpoddersync > > > >And those were just the ones I got notifications for > > > >Best regards > > And the next one > python-django-rest-knox carmelobartolome > https://aur.archlinux.org/pkgbase/python-django-rest-knox/ <https://aur.archlinux.org/pkgbase/python-django-rest-knox/>
python-future, python-tradingeconomics, python-argdispatch, zing-8-bin and python-nipype are also affected (and a lot more too)
Maybe we should emergency auto-reject all packages that add a npm dependency for now?
Did all of these, thanks!
python-future, python-tradingeconomics, python-argdispatch, zing-8-bin and python-nipype are also affected (and a lot more too)
Maybe we should emergency auto-reject all packages that add a npm dependency for now?
Also as far as I can tell, the oldest package to be affected by this campaign is sshuttlee-bin (and the newest one is python-rembg)
On 2026-06-11 17:48, Lex Black wrote:
Am 11. Juni 2026 17:39:33 MESZ schrieb Lex Black <autumn-wind@web.de>:
Hi, Also taken over: nextcloud-git nextcloud-app-integration-google nextcloud-app-repod nextcloud-app-facerecognition nextcloud-app-audioplayer nextcloud-app-twofactor-gateway Python-django-modelcluster
Best regards
Oh, and nextcloud-app-gpoddersync
And those were just the ones I got notifications for
Best regards
I reset all of these, thanks.
On 2026-06-11 17:29, Mark Wagie wrote:
Wow, what a flood.
Indeed
Here's more:
flashfocus: https://aur.archlinux.org/cgit/aur.git/commit/?h=flashfocus&id=7cd3dc436d1f9...
efiboots-git: https://aur.archlinux.org/cgit/aur.git/commit/?h=efiboots-git&id=f01590d8753...
python-privy-git: https://aur.archlinux.org/cgit/aur.git/commit/?h=python-privy-git&id=1a28a8e...
meteo: https://aur.archlinux.org/cgit/aur.git/commit/?h=meteo&id=25051858b9a64dcc3a...
Done, thanks.
On 6/11/26 4:38 PM, Nicolas Boichat wrote:
This as well: https://aur.archlinux.org/cgit/aur.git/commit/?h=ledger-udev-bin&id=d60a201d... This one was already removed by a different moderator.
Thanks for reporting!
First of all: Thanks to everyone! You're all doing amazing work reporting and removing suspicious packages. I couldn't find atomic-lockfile on npm anymore, so it looks like they have already taken action as well.
I couldn't find atomic-lockfile on npm anymore, so it looks like they have already taken action as well.
The NPM package is still up though (I just checked the direct link)
On 6/11/26 4:33 PM, a821 wrote:
more packages with malicious commits and same install function:
- python-apt - python-cerealizer - python-orange - vim-pythonhelper
Thanks, done
Also minitube was infected The package can be removed freely as it's broken since a year Il 11 giugno 2026 15:50:48 CEST, Mark Wagie <mark.wagie@proton.me> ha scritto:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
Hi, another one infected, elmerfem https://aur.archlinux.org/cgit/aur.git/commit/?h=elmerfem&id=3b57b2f1dae3fcd... best regards, On Thu, 11 Jun 2026 16:48:58 +0200 Muflone <webreg@muflone.com> wrote:
Also minitube was infected
The package can be removed freely as it's broken since a year
Il 11 giugno 2026 15:50:48 CEST, Mark Wagie <mark.wagie@proton.me> ha scritto:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
In the last hour, most updates are likely infections. On Thu, 11 Jun 2026 16:57:55 +0200 Patryk Kowalczyk <patryk@kowalczyk.ws> wrote:
Hi, another one infected,
elmerfem
https://aur.archlinux.org/cgit/aur.git/commit/?h=elmerfem&id=3b57b2f1dae3fcd...
best regards,
On Thu, 11 Jun 2026 16:48:58 +0200 Muflone <webreg@muflone.com> wrote:
Also minitube was infected
The package can be removed freely as it's broken since a year
Il 11 giugno 2026 15:50:48 CEST, Mark Wagie <mark.wagie@proton.me> ha scritto:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
On 6/11/26 4:57 PM, Patryk Kowalczyk wrote:
Hi, another one infected,
elmerfem
https://aur.archlinux.org/cgit/aur.git/commit/?h=elmerfem&id=3b57b2f1dae3fcd...
Done, thanks
Hi, In the last hour, most updates are likely infections! There is "ongoing attack". best regards, Patryk On Thu, 11 Jun 2026 16:48:58 +0200 Muflone <webreg@muflone.com> wrote:
Also minitube was infected
The package can be removed freely as it's broken since a year
Il 11 giugno 2026 15:50:48 CEST, Mark Wagie <mark.wagie@proton.me> ha scritto:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
On 6/11/26 4:48 PM, Muflone wrote:
Also minitube was infected
The package can be removed freely as it's broken since a year
Il 11 giugno 2026 15:50:48 CEST, Mark Wagie <mark.wagie@proton.me> ha scritto:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
Thanks, done. I've removed the commit, if somebody has time please submit a deletion request independently.
Hi, The AUR package ktea is also affected. https://aur.archlinux.org/packages/ktea Regards On Thursday, 11 June 2026 at 19:21, Mark Wagie <mark.wagie@proton.me> wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf...
On 11/06/2026 18:11, Shaurya Anand wrote:
Hi, The AUR package ktea is also affected. https://aur.archlinux.org/packages/ktea <https://aur.archlinux.org/ packages/ktea> Regards
Also: python-rembg and noctyra-meta-git -- Frederic Bezies fredbezies@gmail.com Blog: https://blog.fredericbezies-ep.fr/
On 6/11/26 9:50 AM, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr- rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880 <https://aur.archlinux.org/ cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880>
More malware packages recently pushed: - fastjet - lowfi-bin - gnutls3.8.9 User: martinaritter Each of these had the malicious npm install atomic-lockfile added. Best Regards, AlphaLynx
Maybe make the AUR read only for now as we sort out this mess? On Thu, Jun 11, 2026 at 12:36 PM Georg <georg@grgw.de> wrote:
also: https://aur.archlinux.org/packages/autologin
-- Georg
On 6/11/26 9:50 AM, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr- rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880 <https://aur.archlinux.org/ cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880>
Also: - guile-reader - whisper2tr - subsync - imageglass https://aur.archlinux.org/packages?K=ludwinahesse&SeB=m
On 6/11/26 9:50 AM, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr- rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880 <https://aur.archlinux.org/ cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880>
More: - python-coolname - charcoal - sonosano https://aur.archlinux.org/packages?K=filipprochazkova&SeB=m
On 6/11/26 9:50 AM, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr- rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880 <https://aur.archlinux.org/ cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880>
More: - libafterimage - difi - firefox-extension-adnauseam-bin-amo https://aur.archlinux.org/packages?K=teemutanskanen&SeB=m
On 2026-06-11 19:12, AlphaLynx wrote:
On 6/11/26 9:50 AM, Mark Wagie wrote:
A new Maintainer adopted gnome-randr-rust and added an install file with the following:
npm install atomic-lockfile yargs
https://aur.archlinux.org/cgit/aur.git/commit/?h=gnome-randr- rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880 <https://aur.archlinux.org/ cgit/aur.git/commit/?h=gnome-randr-rust&id=da9f4cf2d470bd603968ef605736285a2e0c8880>
More: - libafterimage - difi - firefox-extension-adnauseam-bin-amo
I took care of your three emails, thanks!
This use, aracelirius has a few malicious packages, including yy (clone of yay) which somehow has 89 votes: https://aur.archlinux.org/packages?K=aracelirius&SeB=m
On 2026-06-11 19:49, Mark Wagie wrote:
This use, aracelirius has a few malicious packages, including yy (clone of yay) which somehow has 89 votes:
I’m back! Done, thanks! And yeah, strange that it has 89 votes. They probably voted it up with a bunch of the other accounts to make it seem more legit. Don’t trust the vote count :) -- tippfehlr
participants (17)
-
a821
-
AlphaLynx
-
archlinux.endeared273@passmail.net
-
DodoGTA GT
-
fluf
-
Frederic Bezies
-
Georg
-
Jonathan Grotelüschen
-
Joshua Arnott
-
kpcyrd
-
Lex Black
-
Mark Wagie
-
Matthias Kurz
-
Muflone
-
Nicolas Boichat
-
Patryk Kowalczyk
-
Shaurya Anand