| ▲ | UI_at_80x24 7 hours ago | |||||||||||||||||||||||||||||||||||||
Here's an easy script to scan for compromised packages: https://cscs.pastes.sh/aurvulntest20260611.sh Not my script. It's easy to read/parse. Never pipe a script directly to bash. | ||||||||||||||||||||||||||||||||||||||
| ▲ | sph 6 hours ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||
A quicker alternative:
It's never a bad time to learn about comm(1). | ||||||||||||||||||||||||||||||||||||||
| ▲ | sva_ 6 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||
It isn't guaranteed that the list is conclusive. Always check PKGBUILD and sources, AUR is not to be trusted for the most part. I'm actually more surprised that such compromise hasn't happened earlier. | ||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||
| ▲ | jeroenhd 4 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||
Note that pacman supports date locales; searching for '9 Jun' only works in English locales (or locales using similar formatting, I suppose). After correcting, for me, it flagged "jd-gui", but I had actually installed "jd-gui-bin" about two hours before the compromise. As far as I can tell, I was lucky that I felt lazy that night and went for the -bin package instead of waiting for the source to be compiled. | ||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||