AUR Malware that still presents as of now (30 July 2026, 22:00 UTC)
in format of <package name>/<malicious ELF binary> archutil/linter bigwebapp-manager/minifier boringssl-git/hasher cinnamon-no-nemo/converter duhh/indexer eden-nightly/encryptor garlic-decompiler-gui/checker gigolo-git/tagger gitarbor-bin/parser icloudpd/preprocessor imago-bin/generator juicebox-plus-git/minifier magic-context-dashboard-bin/validator option-term/indexer pagerduty-short-circuiter/assembler portless/assembler pylnker-git/converter pylnker-git/packer python-libipld-git/hasher python-numkong/compressor python-parallax/converter python-ultraplot-git/serializer ramses-git/indexer src-cli-bin/migrator steamidra-bin/generator stirling-pdf-desktop-bin/optimizer wiki-go/merger windscribe-cli-v2-bin/parser
On 7/31/26 12:01 AM, Saren wrote:
in format of <package name>/<malicious ELF binary>
archutil/linter bigwebapp-manager/minifier boringssl-git/hasher cinnamon-no-nemo/converter duhh/indexer eden-nightly/encryptor garlic-decompiler-gui/checker gigolo-git/tagger gitarbor-bin/parser icloudpd/preprocessor imago-bin/generator juicebox-plus-git/minifier magic-context-dashboard-bin/validator option-term/indexer pagerduty-short-circuiter/assembler portless/assembler pylnker-git/converter pylnker-git/packer python-libipld-git/hasher python-numkong/compressor python-parallax/converter python-ultraplot-git/serializer ramses-git/indexer src-cli-bin/migrator steamidra-bin/generator stirling-pdf-desktop-bin/optimizer wiki-go/merger windscribe-cli-v2-bin/parser
Hi, Thanks for the report! I have now handled all of those (banned the account and revert the malicious commit). -- Regards, Robin Candau / Antiz
Hi, The following packages are still infected: bili-tools-git brutefir cardamum-git caveman comodoro-git deepseek-tui-git justevery-code gesso gsimplecal-git human-mcp-git humen-mcp-bin humen-mcp-git i3-workspace-switch-git i915-sriov-dkms kickthemout-git kloak-whonix openrc-manager-gui python-drastic tuigreety-bin zsh-directory-history-git llama.cpp-ggml mimosa-git mingw-w64-vulkan-tools nimf noctyra-cli-git node-llama-cpp play-git python-etcd3 python-twopoint-git python-vxi11 rsbep-backup-git rtk-git rtv-git scenecut-extractor telegram-desktop-futpib-git tempora-bin stable-diffusion.cpp-ggml warp-terminal-dev-bin warp-terminal-git wayland-app-launcher-git weather-display astro-box Regards, Firstpick Robin Candau <antiz@archlinux.org> schrieb am Freitag, 31. Juli 2026 um 01:12:
On 7/31/26 12:01 AM, Saren wrote:
in format of <package name>/<malicious ELF binary>
archutil/linter bigwebapp-manager/minifier boringssl-git/hasher cinnamon-no-nemo/converter duhh/indexer eden-nightly/encryptor garlic-decompiler-gui/checker gigolo-git/tagger gitarbor-bin/parser icloudpd/preprocessor imago-bin/generator juicebox-plus-git/minifier magic-context-dashboard-bin/validator option-term/indexer pagerduty-short-circuiter/assembler portless/assembler pylnker-git/converter pylnker-git/packer python-libipld-git/hasher python-numkong/compressor python-parallax/converter python-ultraplot-git/serializer ramses-git/indexer src-cli-bin/migrator steamidra-bin/generator stirling-pdf-desktop-bin/optimizer wiki-go/merger windscribe-cli-v2-bin/parser
Hi,
Thanks for the report!
I have now handled all of those (banned the account and revert the malicious commit).
-- Regards, Robin Candau / Antiz
On 7/31/26 12:17 PM, firstpick1992 wrote:
Hi,
The following packages are still infected:
bili-tools-git brutefir cardamum-git caveman comodoro-git deepseek-tui-git justevery-code gesso gsimplecal-git human-mcp-git humen-mcp-bin humen-mcp-git i3-workspace-switch-git i915-sriov-dkms kickthemout-git kloak-whonix openrc-manager-gui python-drastic tuigreety-bin zsh-directory-history-git llama.cpp-ggml mimosa-git mingw-w64-vulkan-tools nimf noctyra-cli-git node-llama-cpp play-git python-etcd3 python-twopoint-git python-vxi11 rsbep-backup-git rtk-git rtv-git scenecut-extractor telegram-desktop-futpib-git tempora-bin stable-diffusion.cpp-ggml warp-terminal-dev-bin warp-terminal-git wayland-app-launcher-git weather-display astro-box
Regards, Firstpick
Hi, Thanks for the report! We should have acted on all infected packages now (including the above list). If some packages slipped through, please tell us. -- Regards, Robin Candau / Antiz
On Jul 31, 2026, 7:15 PM, Robin Candau <antiz@archlinux.org> wrote:
On 7/31/26 12:17 PM, firstpick1992 wrote:
Hi,
The following packages are still infected:
bili-tools-git brutefir cardamum-git caveman comodoro-git deepseek-tui-git justevery-code gesso gsimplecal-git human-mcp-git humen-mcp-bin humen-mcp-git i3-workspace-switch-git i915-sriov-dkms kickthemout-git kloak-whonix openrc-manager-gui python-drastic tuigreety-bin zsh-directory-history-git llama.cpp-ggml mimosa-git mingw-w64-vulkan-tools nimf noctyra-cli-git node-llama-cpp play-git python-etcd3 python-twopoint-git python-vxi11 rsbep-backup-git rtk-git rtv-git scenecut-extractor telegram-desktop-futpib-git tempora-bin stable-diffusion.cpp-ggml warp-terminal-dev-bin warp-terminal-git wayland-app-launcher-git weather-display astro-box
Regards, Firstpick
Hi,
Thanks for the report!
We should have acted on all infected packages now (including the above list). If some packages slipped through, please tell us.
-- Regards, Robin Candau / Antiz
There is also a pandoc one now, by user alicemarty, which includes a (most likely) malicious file named bundler in sources. Sent a deletion request via aur web interface.
On 8/1/26 12:38 PM, contact@octavianflorea.net wrote:
On Jul 31, 2026, 7:15 PM, Robin Candau <antiz@archlinux.org> wrote:
On 7/31/26 12:17 PM, firstpick1992 wrote:
Hi,
The following packages are still infected:
bili-tools-git brutefir cardamum-git caveman comodoro-git deepseek-tui-git justevery-code gesso gsimplecal-git human-mcp-git humen-mcp-bin humen-mcp-git i3-workspace-switch-git i915-sriov-dkms kickthemout-git kloak-whonix openrc-manager-gui python-drastic tuigreety-bin zsh-directory-history-git llama.cpp-ggml mimosa-git mingw-w64-vulkan-tools nimf noctyra-cli-git node-llama-cpp play-git python-etcd3 python-twopoint-git python-vxi11 rsbep-backup-git rtk-git rtv-git scenecut-extractor telegram-desktop-futpib-git tempora-bin stable-diffusion.cpp-ggml warp-terminal-dev-bin warp-terminal-git wayland-app-launcher-git weather-display astro-box
Regards, Firstpick
Hi,
Thanks for the report!
We should have acted on all infected packages now (including the above list). If some packages slipped through, please tell us.
-- Regards, Robin Candau / Antiz
There is also a pandoc one now, by user alicemarty, which includes a (most likely) malicious file named bundler in sources. Sent a deletion request via aur web interface.
Thanks for the report, deleted! -- Regards, Robin Candau / Antiz
Hi, 19 more infected AUR packages contain malware executed via sudo during builds: accounts-qml-module-bin arch-update-bin aur-sync-vote-bin bridge-utils-bin byobu-bin fsearch-bin gtk-engine-murrine-bin gtk2-bin http-parser-bin jellium-desktop-git-bin mangowm-bin mbedtls2-bin openssl-1.1-bin plasma6-applets-panel-colorizer-bin python-inputs-bin python-steam-bin splix-bin tuxmanager-bin grub-customizer-bin Robin Candau <antiz@archlinux.org> schrieb am Freitag, 31. Juli 2026 um 19:32:
On 7/31/26 12:17 PM, firstpick1992 wrote:
Hi,
The following packages are still infected:
bili-tools-git brutefir cardamum-git caveman comodoro-git deepseek-tui-git justevery-code gesso gsimplecal-git human-mcp-git humen-mcp-bin humen-mcp-git i3-workspace-switch-git i915-sriov-dkms kickthemout-git kloak-whonix openrc-manager-gui python-drastic tuigreety-bin zsh-directory-history-git llama.cpp-ggml mimosa-git mingw-w64-vulkan-tools nimf noctyra-cli-git node-llama-cpp play-git python-etcd3 python-twopoint-git python-vxi11 rsbep-backup-git rtk-git rtv-git scenecut-extractor telegram-desktop-futpib-git tempora-bin stable-diffusion.cpp-ggml warp-terminal-dev-bin warp-terminal-git wayland-app-launcher-git weather-display astro-box
Regards, Firstpick
Hi,
Thanks for the report!
We should have acted on all infected packages now (including the above list). If some packages slipped through, please tell us.
-- Regards, Robin Candau / Antiz
Hi, 27 more infected AUR packages contain malware executed via sudo during builds: aic94xx-firmware-bin aur-scanner-bin debtap-bin hexchat-bin fvs2-bin gnu-netcat-bin gtk2-ng-git-bin howdy-next-bin hyprkeys-git-bin noctalia-git-bin nomacs-bin octopi-bin aurutils-bin plasma6-applets-appgrid-bin proton-rtsp pwvucontrol-bin qt5-location-bin qt5-sensors-bin qt5-websockets-bin ttf-symbola-bin woeusb-ng-bin xfwm4-themes-bin xclicker-bin xdg-terminal-exec-bin linux-cachyos-bin paru-git-bin syncthingtray-qt6-bin
Hi,
19 more infected AUR packages contain malware executed via sudo during builds:
accounts-qml-module-bin arch-update-bin aur-sync-vote-bin bridge-utils-bin byobu-bin fsearch-bin gtk-engine-murrine-bin gtk2-bin http-parser-bin jellium-desktop-git-bin mangowm-bin mbedtls2-bin openssl-1.1-bin plasma6-applets-panel-colorizer-bin python-inputs-bin python-steam-bin splix-bin tuxmanager-bin grub-customizer-bin
Robin Candau <antiz@archlinux.org> schrieb am Freitag, 31. Juli 2026 um 19:32:
On 7/31/26 12:17 PM, firstpick1992 wrote:
Hi,
The following packages are still infected:
bili-tools-git brutefir cardamum-git caveman comodoro-git deepseek-tui-git justevery-code gesso gsimplecal-git human-mcp-git humen-mcp-bin humen-mcp-git i3-workspace-switch-git i915-sriov-dkms kickthemout-git kloak-whonix openrc-manager-gui python-drastic tuigreety-bin zsh-directory-history-git llama.cpp-ggml mimosa-git mingw-w64-vulkan-tools nimf noctyra-cli-git node-llama-cpp play-git python-etcd3 python-twopoint-git python-vxi11 rsbep-backup-git rtk-git rtv-git scenecut-extractor telegram-desktop-futpib-git tempora-bin stable-diffusion.cpp-ggml warp-terminal-dev-bin warp-terminal-git wayland-app-launcher-git weather-display astro-box
Regards, Firstpick
Hi,
Thanks for the report!
We should have acted on all infected packages now (including the above list). If some packages slipped through, please tell us.
-- Regards, Robin Candau / Antiz
Hi team, Does the list also include malware?
Brave origin Nightly bin Because i use Brave origin Nightly bin
On Sat, 1 Aug, 2026, 8:47 pm firstpick1992, <firstpick1992@proton.me> wrote:
Hi,
27 more infected AUR packages contain malware executed via sudo during builds:
aic94xx-firmware-bin aur-scanner-bin debtap-bin hexchat-bin fvs2-bin gnu-netcat-bin gtk2-ng-git-bin howdy-next-bin hyprkeys-git-bin noctalia-git-bin nomacs-bin octopi-bin aurutils-bin plasma6-applets-appgrid-bin proton-rtsp pwvucontrol-bin qt5-location-bin qt5-sensors-bin qt5-websockets-bin ttf-symbola-bin woeusb-ng-bin xfwm4-themes-bin xclicker-bin xdg-terminal-exec-bin linux-cachyos-bin paru-git-bin syncthingtray-qt6-bin
Hi,
19 more infected AUR packages contain malware executed via sudo during
builds:
accounts-qml-module-bin arch-update-bin aur-sync-vote-bin bridge-utils-bin byobu-bin fsearch-bin gtk-engine-murrine-bin gtk2-bin http-parser-bin jellium-desktop-git-bin mangowm-bin mbedtls2-bin openssl-1.1-bin plasma6-applets-panel-colorizer-bin python-inputs-bin python-steam-bin splix-bin tuxmanager-bin grub-customizer-bin
Robin Candau <antiz@archlinux.org> schrieb am Freitag, 31. Juli 2026 um
19:32:
On 7/31/26 12:17 PM, firstpick1992 wrote:
Hi,
The following packages are still infected:
bili-tools-git brutefir cardamum-git caveman comodoro-git deepseek-tui-git justevery-code gesso gsimplecal-git human-mcp-git humen-mcp-bin humen-mcp-git i3-workspace-switch-git i915-sriov-dkms kickthemout-git kloak-whonix openrc-manager-gui python-drastic tuigreety-bin zsh-directory-history-git llama.cpp-ggml mimosa-git mingw-w64-vulkan-tools nimf noctyra-cli-git node-llama-cpp play-git python-etcd3 python-twopoint-git python-vxi11 rsbep-backup-git rtk-git rtv-git scenecut-extractor telegram-desktop-futpib-git tempora-bin stable-diffusion.cpp-ggml warp-terminal-dev-bin warp-terminal-git wayland-app-launcher-git weather-display astro-box
Regards, Firstpick
Hi,
Thanks for the report!
We should have acted on all infected packages now (including the above list). If some packages slipped through, please tell us.
-- Regards, Robin Candau / Antiz
On 8/1/26 1:03 PM, firstpick1992 wrote:
Hi,
19 more infected AUR packages contain malware executed via sudo during builds:
accounts-qml-module-bin arch-update-bin aur-sync-vote-bin bridge-utils-bin byobu-bin fsearch-bin gtk-engine-murrine-bin gtk2-bin http-parser-bin jellium-desktop-git-bin mangowm-bin mbedtls2-bin openssl-1.1-bin plasma6-applets-panel-colorizer-bin python-inputs-bin python-steam-bin splix-bin tuxmanager-bin grub-customizer-bin
Hi, Thanks for the report. I acted on those (deleted the package and banned the account). For the record, those are all new packages (not orphaned packages being adopted). I assume more will come, we'll clean those as soon as possible. In the mean time stay vigilant, probably refrain from installing freshly pushed new packages from the AUR for now. -- Regards, Antiz / Robin Candau
Robin and team, suddenly our packages related to https://github.com/manticore-projects/aurscan aurscan-manticore-bin-release-git aurscan-manticore-release are not available in AUR anymore. May I ask why and how to bring them back? Thank you, best and cheers Andreas
On 8/2/26 9:00 AM, Andreas Reichel wrote:
Robin and team,
suddenly our packages related to https://github.com/manticore-projects/ aurscan <https://github.com/manticore-projects/aurscan>
aurscan-manticore-bin-release-git aurscan-manticore-release
are not available in AUR anymore. May I ask why and how to bring them back?
Thank you, best and cheers Andreas
Hi Andreas, Apparently, the first one got deleted [1] because it did not respect our VCS packaging guidelines [2] and therefore needs fixes before being pushed again. As far as I can tell, the second one never existed on the AUR however. Pushes to the AUR are currently disabled while we handle the situation, you'll need to wait for that before being able to push them again. No ETA to share for now unfortunately. Sorry for the inconvenience. [1] https://lists.archlinux.org/archives/list/aur-requests@lists.archlinux.org/t... [2] https://manual.archlinux.page/package-guidelines/vcs/ -- Regards, Robin Candau / Antiz
Robin and Team, On Sun, 2026-08-02 at 09:27 +0200, Robin Candau wrote:
Apparently, the first one got deleted [1] because it did not respect our VCS packaging guidelines [2] and therefore needs fixes before being pushed again.
Ok, thank you for the hint. We would fix this of course asap.
Pushes to the AUR are currently disabled while we handle the situation, you'll need to wait for that before being able to push them again. No ETA to share for now unfortunately. Sorry for the inconvenience.
No inconvenience at all, we fight for the same team and there are bigger issues present right now. We will wait patiently and come back with a more correct packaging. Thank you for all your work and prompt response. Best and cheers Andreas
Robin, apologies for asking a naive question: is a prompt delete without any probation time or warning the best practise? Or did we just fall into a bad timing period? I would have thought that a change request with a 48h resolution window was nice. Best and cheers Andreas
participants (6)
-
Amal krishna
-
Andreas Reichel
-
contact@octavianflorea.net
-
firstpick1992
-
Robin Candau
-
Saren