I use Malware BTW
Out of 12 installed AUR packages, I had 0 effected.
Maybe they forgot to include the Effects™ Library?
Doh! Not gonna change it.
Best laugh today!
radarr, sonarr and jellyfin client are all safe, phew
Is this newly submitted packages which are malware, or existing packages which had malware introduced to them? And is there a list of affected packages anywhere?
They’re existing packages that were abandoned by the original authors and then had ownership claimed by malicious parties
It looks like they were existing packages.
List here: https://cscs.pastes.sh/raw/aurvulnlist20260611.txt
Got that from: https://discuss.cachyos.org/t/aur-compromised-1500-packages-affected-20260611/31040
They have a script that can check if you have any of them.Thanks, looks like I’m ok





