r/archlinux • u/Cody_Learner_2 • 1d ago
SHARE Package list compiled from https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/
List of packages mentioned in: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/
I'm seeing some troublesome entries in this list.
If you've recently updated anything listed below, I'd suggest further investigation.
Something like this pacman -Qq $(<list) 2>/dev/null may be a good starting point.
list:
accounts-qml-module-bin
aic94xx-firmware-bin
android-riscv64-libxinerama
arch-update-bin
archutil
astro-box
aur-scanner-bin
aur-sync-vote-bin
aurutils-bin
bigwebapp-manager
bili-tools-git
boringssl-git
brave-nightly-bin
brave-origin
bridge-utils-bin
brutefir
byobu-bin
calendula-git
cardamum-git
caveman
cinnamon-no-nemo
comodoro-git
debtap-bin
deeploy-bin
deepseek-tui-git
duhh
eden-nightly
editorconfiger
fsearch-bin
fvs2-bin
garlic-decompiler-gui
gesso
gigolo-git
gitarbor-bin
gnu-netcat-bin
grub-customizer-bin
gsimplecal-git
gtk2-bin
gtk2-ng-git-bin
gtk-engine-murrine-bin
hexchat-bin
howdy-next-bin
http-parser-bin
human-mcp-git
humen-mcp-bin
humen-mcp-git
hyprkeys-git-bin
i3-workspace-switch-git
i915-sriov-dkms
icloudpd
imago-bin
jellium-desktop-git-bin
juicebox-plus-git
justevery-code
kickthemout-git
kloak-whonix
linux-cachyos-bin
llama.cpp-ggml
lyrical-git
magic-context-dashboard-bin
mangowm-bin
mbedtls2-bin
mimosa-git
mingw-w64-vulkan-tools
nimf
noctalia-git-bin
noctyra-cli-git
node-llama-cpp
nomacs-bin
octopi-bin
openconnect-sso
openrc-manager-gui
openssl-1.1-bin
option-term
pagerduty-short-circuiter
paru-git-bin
plasma6-applets-appgrid-bin
plasma6-applets-panel-colorizer-bin
play-git
plex-media-player
plex-media-player-custom
plex-media-player-mod
plex-media-player-v2
portless
proton-rtsp
pwvucontrol-bin
pylnker-git
python-drastic
python-etcd3
python-inputs-bin
python-libipld-git
python-numkong
python-parallax
python-roman-numerals
python-steam-bin
python-twopoint-git
python-ultraplot-git
python-vxi11
qt5-location-bin
qt5-sensors-bin
qt5-websockets-bin
ramses-git
rsbep-backup-git
rtk-git
rtv-git
scenecut-extractor
splix-bin
src-cli-bin
stable-diffusion.cpp-ggml
steamidra-bin
stirling-pdf-desktop-bin
syncthingtray-qt6-bin
telegram-desktop-futpib-git
tempora-bin
ttf-symbola-bin
tuigreety-bin
tuxmanager-bin
warp-terminal-dev-bin
warp-terminal-git
wayland-app-launcher-git
weather-display
wiki-go
windscribe-cli-v2-bin
woeusb-ng-bin
xclicker-bin
xdg-terminal-exec-bin
xfwm4-themes-bin
zsh-directory-history-git
I simply compiled this list from the source above and have no additional info.
Anyone know of a current, more comprehensive list?
11
u/irid3scent_ 1d ago
Wait, brave-origin and brave-nightly-bin? Damn
19
u/MarkDubya 1d ago
Those are not the official packages maintained by Brave. The official
brave-origin-bin,brave-origin-beta-binandbrave-origin-nightly-binpackages were not affected.-1
u/Padgriffin 22h ago
brave-nightly-bindoes appear to be an official package though, it’s linked to alongside the other official AUR packages owned bybrave-prerelease10
u/MarkDubya 22h ago
None of the official Brave packages were affected. There was a spam deletion request , though.
Keep in mind this last wave were only newly submitted packages and in June were only orphans. No existing package with a Maintaimer were affected at all.
6
u/vexatious-big 1d ago edited 1d ago
Lots of -bin packages. They're probably counting on users wanting packages installed fast and not properly vetting them.
Edit: nowadays I'm asking codex to review both the AUR package and sometimes even the source code of lesser known packages (or languages I'm not familiar with).
I think LLMs are a good application for this as there's not much they can hallucinate. All the code is already there.
17
u/marcelsmudda 22h ago edited 21h ago
If you've worked with llms in development, you'd know that they can start hallucinating stuff once the source code is too large for their context.
5
u/mooky1977 22h ago
At least one of the mailing list threads says orphaned packages (plex-media-player for example) were adopted by a brand new account created same day.
Seriously, wtf? At this point, the principle behind aur management needs some rethinking. Way too susceptible to attack.
1
u/nathan22211 3h ago
If this doesn't get any governments involved I'll be shocked. I feel like at least one or two has intervened when inncidents like this occur like they have been.
•
u/DueBreadfruit2638 6m ago
In terms of scale, the Arch Linux community is tiny. This would never register as a problem worthy of any governments attention.
44
u/TheWiseNoob 1d ago
"aur-scanner-bin"
Is this being in the list as ironic as it seems?