← 返回日报
预计 1 分钟

Malware in Arch Linux AURs now inserting Russian spam into shell configs

摘要

标题为 Malware in Arch Linux AURs now inserting Russian spam into shell configs。作者 Sid Karunaratne 于 2026 年 6 月 14 日发布报告,指出 GitHub 上的多个 AUR 仓库中软件包在安装后会在 bash/zsh 等 shell 配置中添加 echo 俄语垃圾邮件内容。通过 git grep --files-with-matches 'NoServices' 在所有 refs remotes/origin 下搜索匹配,列出完整包名列表:algobox alist-desktop-bin arpoison asymptote-git aurbs blackfire-cli ccsm-git chinadns closure-hib cmaptools cypher-shell daggerfall-fixes dbacl docan-bin docan-unstable emacs-evil enyo-launcher esy faudio-git findwild gbdk gnome-pomodoro-git hidapi-git hypatia infer kicadlibrarian libdmx libparserutils-git llama.cpp-sycl-f16-git nikto-git nodejs-serverless nodejs-uglifycss nullfs-dkms-git onivim2-git onvifviewer pcb pcmanx-gtk2-git perl-xml-filter-domfilter-libxml pfqueue pgdbf plasma-theme-helium plataro-icons pngrim-git proteus-hib psychopy purple-gowhatsapp python-cmake-bin python-graphsrv python-imagebackup python-json2html python-llama-cpp-hip python-monkeytype python-pytest-filedata python-tmpl redocly rigsofrods-bin ruby-open uri redirections ruby-snapsync samsung-ssd-dc-toolkit scd softmaker-office-2012-bin spacebar-client-git spacebar-git swig2 systemtap-git tapeutape thomaswasalone-hib ttf-dotsies tuwunel-git ultimatevocalremovergui-git vaping vim-railscasts zenta-git。后续 Jonathan Grotelüschen 回复称团队正努力重置/删除恶意提交并封禁账号,欢迎举报更多包。

荐读理由

邮件仅提醒包内恶意提交与删除行动,未提供可迁移到项目的工具、改变判断的洞见、真实技术变化、创业信号或高价值信息,纯属已知常识或标题党类型

原文

thread

Re: AUR REPORT THREAD

Sid Karunaratne

14 Jun 2026 14 Jun '26

6:03 p.m.

Not exactly malicious, but definitely spam. Using the github AUR repo: In all these cases it adds to bash/zsh etc shell configs to echo spam, in russian, on start. $ while read ref; do git grep --files-with-matches 'NoServices' $ref; done < <( git refs list --format '%(refname)' ) | grep -Po '(?<=refs/remotes/origin/).*' | sort | tee NoServices.txt algobox alist-desktop-bin arpoison asymptote-git aurbs blackfire-cli ccsm-git chinadns closure-hib cmaptools cypher-shell daggerfall-fixes dbacl docan-bin docan-unstable emacs-evil enyo-launcher esy faudio-git findwild gbdk gnome-pomodoro-git hidapi-git hypatia infer kicadlibrarian libdmx libparserutils-git llama.cpp-sycl-f16-git nikto-git nodejs-serverless nodejs-uglifycss nullfs-dkms-git onivim2-git onvifviewer pcb pcmanx-gtk2-git perl-xml-filter-domfilter-libxml pfqueue pgdbf plasma-theme-helium plataro-icons pngrim-git proteus-hib psychopy purple-gowhatsapp python-cmake-bin python-graphsrv python-imagebackup python-json2html python-llama-cpp-hip python-monkeytype python-pytest-filedata python-tmpl redocly rigsofrods-bin ruby-open_uri_redirections ruby-snapsync samsung-ssd-dc-toolkit scd softmaker-office-2012-bin spacebar-client-git spacebar-git swig2 systemtap-git tapeutape thomaswasalone-hib ttf-dotsies tuwunel-git ultimatevocalremovergui-git vaping vim-railscasts zenta-git (It was always in PKGBUILD, so I removed the ":PKGBUILD" from the output) On Thu, 11 Jun 2026, at 13:47, Jonathan Grotelüschen wrote:

...

Hi everyone,

we’re working hard to reset/delete all malicious commits and ban the accounts.

If you find more malicious packages, please send them as a reply to this email to keep them all in one thread.

Thanks!

-- tippfehlr

Attachments: • OpenPGP_signature.asc

Attachments:

**

Back to the thread

** Back to the list

Lobsters · 4 赞 · 0 评 讨论 → 阅读原文 →

这条对你有帮助吗?