← 返回日报
精读 预计 1 分钟

Arch Linux AUR Hit By Another Wave Of Now More Sophisticated Malware Attack

摘要

继昨日 1500 多个包受影响后,AUR 再次发现新一轮恶意攻击。此次攻击手段更隐蔽,采用了代码混淆技术以隐藏恶意意图。受影响范围涵盖 Node.js 包、Plasma 6 小部件、Firefox 扩展、Aura 浏览器及 NeoVim 插件等。部分恶意代码由开发者利用 Gemma E2B AI 模型检测发现,目前受影响的包已得到处理,社区正在讨论是否应加强 AUR 的安全验证机制。

荐读理由

关注文中利用本地 AI 模型(Gemma E2B)识别混淆恶意代码的工程案例,这为你处理非受信第三方依赖包或构建自动化安全审计工具提供了具体的技术可行性参考。

原文

Arch Linux AUR Hit By Another Wave Of Now More Sophisticated Malware Attack

Written by Michael Larabel in Arch Linux on 14 June 2026 at 06:32 AM EDT. 27 Comments

ARCH LINUX

Just a day after Arch Linux developers believed they got their malware AUR incident under control with 1,500+ packages affected by malware, another round of of AUR malware is now being discovered. This latest round is more sophisticated as with code obfuscation to better conceal the intent.

Last night another round of malware in Arch Linux AUR packages was reported by developer a821. Various Node.js packages, a Plasma 6 applets package, some Firefox packages, the Aura browser, LibreWolf extensions, a NeoVim plug-in, and various other packages were all found with malware via obfuscated code. Shortly thereafter a821 reported back that the affected packages were taken care of.

Hours later, Nicolas Boichat reported more malware in AUR packages. Boichat discovered those latest malware bits using a local Gemma E2B AI model. The new malware attempt in AUR was described as "a bit more elaborate" in obfuscating the action around the Bun command.

obfuscated malware install command example

At this stage it's a bit surprising they don't completely shutdown AUR until they can better verify the security and safety of this user-supplied repository or at least implement new safeguards on changes.

Lobsters · 2 赞 · 4 评 讨论 → 阅读原文 →

这条对你有帮助吗?