frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Arch Linux pulls AUR packages that installed Chaos RAT malware

https://www.bleepingcomputer.com/news/security/arch-linux-pulls-aur-packages-that-installed-chaos-rat-malware/
6•mikece•3h ago

Comments

lr0•3h ago
I remember when I was using Arch around 5 years ago and I was looking for the Brave browser package, when I found it could be only be installed through the AUR, for some reason I had the assumption that since it's hosted on Arch's official servers it must be properly reviewed even if it was built by the community (like how Chrome web extensions are, for example). And I installed so many AUR packages for things that I used to manually install or find a workaround to install their .deb file on my Arch (using dpkg[0] for example). Then, I was in IRC and I found two fellows talking about "trusting" the AUR, and you can imagine the rest. I started an AUR-detox.

Before moving totally from Arch I kept some AUR packages that I could not let go of, but on the condition of checking their scripts thoroughly and making sure to check them even more thoroughly with each update, and only updating them when it's really necessary. I'm not sure if other Linux package repositories (like Nix) have these supply-chain-attack possibilities or if they employ a better review mechanism, but I really hope if Arch maintainers can find a solution to make the AUR safer, at least more than how it currently sounds.

[0]: https://tracker.debian.org/pkg/dpkg

jolmg•3m ago
This is also why AUR helpers are unofficial and the packages don't come prebuilt. The official way to use the AUR is very manual. You have to download the PKGBUILD and accompanying files manually (git clone, etc.), review the files, then `makepkg`, then `pacman -U`. It's in the wiki article for the AUR:

https://wiki.archlinux.org/title/Arch_User_Repository

It even says:

> 2. Verify that the PKGBUILD and accompanying files are not malicious or untrustworthy.

> but I really hope if Arch maintainers can find a solution to make the AUR safer

Safe packages go on the official repos. The entire point of the AUR is to be a low-friction repo for Arch users to share their packages. A "safe" AUR is to have no AUR and just have the official repos.

Show HN: Summary, topic, bullet points, references for popular HN posts

https://extraakt.com/extraakts
1•guybedo•45s ago•0 comments

How to spot fake products on AliExpress

1•FakeFind_ai•3m ago•0 comments

Bun adds pnpm-style isolated installation mode

https://github.com/oven-sh/bun/pull/20440
1•nateb2022•4m ago•0 comments

Patient-Specific in Vivo Gene Editing to Treat a Rare Genetic Disease

https://www.nejm.org/doi/full/10.1056/NEJMoa2504747
1•richardboegli•5m ago•0 comments

First Patient Treated with Personalized CRISPR Gene Editing Therapy

https://www.chop.edu/news/worlds-first-patient-treated-personalized-crispr-gene-editing-therapy-childrens-hospital
1•richardboegli•8m ago•0 comments

Reddit users in the UK must now upload selfies to access NSFW subreddits

https://mashable.com/article/reddit-age-verification-check-uk-law-online-safety
3•echelon•14m ago•0 comments

The Seductions of A.I. For the Writer's Mind

https://www.nytimes.com/2025/07/18/opinion/ai-chatgpt-school.html
1•pseudolus•23m ago•1 comments

Mr Browser – Macintosh Repository file downloader that runs directly on 68k Macs

https://www.macintoshrepository.org/44146-mr-browser
1•zdw•26m ago•0 comments

Tokyo's retro shotengai arcades are falling victim to gentrification

https://www.theguardian.com/world/2025/jul/18/cult-of-convenience-how-tokyos-retro-shotengai-arcades-are-falling-victim-to-gentrification
2•pseudolus•30m ago•0 comments

Control issues and ditching involving RPA swarm of 500 Damoda Newton 2.2 RPA

https://www.atsb.gov.au/publications/investigation_reports/2025/report/ao-2023-033
1•oliverdunk•33m ago•0 comments

Intel Announces It's Shutting Down Clear Linux

https://www.phoronix.com/news/Intel-Ends-Clear-Linux
7•gpi•35m ago•1 comments

Microsoft to stop using engineers in China for tech support of US Military

https://www.reuters.com/world/us/microsoft-stop-using-engineers-china-tech-support-us-military-hegseth-orders-2025-07-18/
4•miles•36m ago•0 comments

Playing Online Nintendo 64 Games with a Flashcart [video]

https://www.youtube.com/watch?v=v9aVrBq0aiY
5•giovannibajo1•37m ago•0 comments

Debcraft – Easiest way to modify and build Debian packages

https://optimizedbyotto.com/post/debcraft-easy-debian-packaging/
3•pabs3•42m ago•0 comments

Were Americans ever really healthy?

https://www.bloomberg.com/news/features/2025-07-18/was-the-us-ever-healthy-what-maha-gets-wrong-about-nutrition-history
2•zinekeller•43m ago•0 comments

How to Write Great Prompts for String

https://pipedream.com/blog/how-to-write-great-prompts-for-string/
1•todsacerdoti•45m ago•0 comments

Reinventing the Python Wheel

https://lwn.net/Articles/1028299/
1•zahlman•50m ago•0 comments

Why don't I drink? How much time you got?

https://shaungallagher.pressbin.com/blog/drinking.html
3•jawns•50m ago•0 comments

"Far out, man": how Jimi Hendrix boosted the career of Sha Na Na (2024)

https://faroutmagazine.co.uk/how-jimi-hendrix-boosted-the-career-of-sha-na-na
2•thomassmith65•52m ago•0 comments

Build an AI Agent Web App with String and Lovable

https://pipedream.com/blog/build-an-ai-agent-with-string-lovable/
1•todsacerdoti•52m ago•0 comments

Cascading retrieval with multi-vector representations

https://www.pinecone.io/blog/cascading-retrieval-with-multi-vector-representations/
1•gk1•58m ago•0 comments

What a bumble bee chooses to eat may not match its ideal diet

https://phys.org/news/2025-07-bumble-bee-ideal-diet.html
1•PaulHoule•59m ago•0 comments

Shutting Down Clear Linux OS

https://community.clearlinux.org/t/all-good-things-come-to-an-end-shutting-down-clear-linux-os/10716
48•todsacerdoti•1h ago•26 comments

Nuxt Joins Vercel

https://vercel.com/blog/nuxtlabs-joins-vercel
1•rattray•1h ago•1 comments

The Kap Programming Language

https://kapdemo.dhsdevelopments.com/examples.html
2•thunderbong•1h ago•0 comments

A Software for One

https://www.jasonthorsness.com/30
2•jasonthorsness•1h ago•0 comments

Women Are Falling Behind in America's Return to the Office

https://www.wsj.com/lifestyle/careers/return-to-office-gender-gap-236392aa
5•bdev12345•1h ago•2 comments

Astronomer launches internal investigation after viral Coldplay video

https://www.cnn.com/2025/07/18/entertainment/coldplay-concert-kiss-cam-astronomer-investigation
2•bb88•1h ago•0 comments

Build your CV on Subreply as a LinkedIn alternative

https://subreply.com/lm
4•lcnmrn•1h ago•0 comments

Curse Not the King

https://daringfireball.net/2025/07/curse_not_the_king_cbs_colbert_trump
2•Bogdanp•1h ago•0 comments