frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages

https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
68•qwertox•1h ago

Comments

embedding-shape•53m ago
As always a fair reminder to not install random 3rd party packages/libraries/applications without reviewing them, especially when there is zero vetting. Luckily this was constrained to AUR, which basically is a free-for-all package repository, with users being warned multiple times that it's vital to review anything before you install it, compared to the official repositories.

`rua` and other similar CLIs make it really easy to review the packages before installing them from AUR too, and if you are doing banking on the same computer, you really have no excuse not to review the software you depend on. Keeping the amount of packages low, only use what you need, also makes this a whole lot simpler when it's time to upgrade.

tryauuum•51m ago
How bad was it?
graemep•42m ago
1,500 packages out of 107,000 so pretty bad, ameliorated by only affecting installs of those in a window of a few days.

AUR comes with a warning that its up to you to check what you install from there.

maxerickson•8m ago
I wonder what typical AUR usage looks like. I apparently have 27 packages installed and last updated one in November.
__s•2m ago
I was concerned at headline, then saw "oh just AUR"

Next up, "millions of malicious packages still not taken down on internet"

anthonj•35m ago
I cringed hard when some people started to make pacman wrappers that could install from AUR directly.

I've installed stuff from the aur before but most of the times I prefer to skip the middleman and just navigate to the project website. A premade pkgbuild is not convenient enough to take the risk of typoquatting or the tactical npm or pip dependency.

Grombobulous•14m ago
For me, this tradeoff isn’t worth it. I didn’t switch to Linux so that I can waste time going to websites and clicking “download” to update my programs like a Windows user.

The pacman wrappers you mention are crazy, though.

pixelpoet•9m ago
> typoquatting

Perfect demonstration!

OJFord•7m ago
`yay` (one such wrapper) shows me the PKGBUILD diff on every update. The first time I install something I verify the URL, and check any install script etc. seems sensible; the vast majority of subsequent updates are changes to just version number & checksum. A typosquat attack would be very obvious.

(It's a bit vulnerable to it on first install, but so is 'just navigate to the project website [and click download]'.)

Havoc•21m ago
As I undertood it this was mostly orphaned packages?
Shank•9m ago
That's correct, orphaned packages could be adopted seemingly automatically, so someone did and then published malware in bulk.
robby_w_g•10m ago
I’ve made a point of not installing any AUR packages. It’s really tempting when there’s a package that’s not available via pacman, but at the end of the day I’d rather build from source myself or use a docker image.

A low-carbon computing platform from your retired phones

https://research.google/blog/a-low-carbon-computing-platform-from-your-retired-phones/
89•vikas-sharma•3h ago•35 comments

Show HN: 2 Weeks of Hallucinate – The Photo Gallery

https://hallucinate.site/gallery
33•stagas•1h ago•7 comments

An Interview with Intel's Kira Boyko: Xeon 6's Product Director

https://chipsandcheese.com/p/an-interview-with-intels-kira-boyko
10•lumpa•1h ago•0 comments

Leaving Mozilla

https://blog.unitedheroes.net/5751
320•martey•7h ago•186 comments

The state of building user interfaces in Rust

https://areweguiyet.com/#ecosystem
45•mahirsaid•2d ago•21 comments

AI OSS tool repo goes archived over night after raising $7.3M Seed

https://github.com/tensorzero/tensorzero
15•hek2sch•1h ago•1 comments

Electric motors with no rare earths

https://www.renaultgroup.com/en/magazine/energy-and-powertrains/all-about-electric-motors-with-no...
548•bestouff•15h ago•162 comments

Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages

https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
68•qwertox•1h ago•12 comments

Statement on US government directive to suspend access to Fable 5 and Mythos 5

https://www.anthropic.com/news/fable-mythos-access
2642•Dylan1312•12h ago•1921 comments

CRISPR tech selectively shreds cancer cells, including "undruggable" cancers

https://innovativegenomics.org/news/crispr-technique-selectively-shreds-cancer-cells/
866•gmays•22h ago•196 comments

Show HN: Paca – Lightweight Jira alternative for human-AI collaboration

https://github.com/Paca-AI/paca
52•pikann22•3h ago•22 comments

Open source AI must win

https://opensourceaimustwin.com/?share=v2
1165•vednig•11h ago•368 comments

There is a shadow hanging over this Fable thing

https://12gramsofcarbon.com/p/tech-things-there-is-a-massive-shadow
344•theahura•8h ago•314 comments

How to setup a local coding agent on macOS

https://ikyle.me/blog/2026/how-to-setup-a-local-coding-agent-on-macos
408•kkm•19h ago•102 comments

The computer science degree isn’t dead

https://spectrum.ieee.org/computer-science-degree-isnt-dead
125•jnord•3d ago•114 comments

Show HN: Putt.day a daily mini golf game

https://putt.day/
217•ellg•14h ago•91 comments

Malware developers added nuclear and biological weapons text to to their spyware

https://twitter.com/jsrailton/status/2064661778978533571
418•marc__1•1d ago•225 comments

Labor Is a Market Distortion, we need VAT and UBI

https://wilsoniumite.com/2026/06/07/labor-is-a-market-distortion/
6•Wilsoniumite•2h ago•3 comments

Swift at Apple: Migrating the TrueType hinting interpreter

https://www.swift.org/blog/migrating-truetype-hinting-to-swift/
212•DASD•17h ago•98 comments

Twenty One Zero-Days in FFmpeg

https://depthfirst.com/research/21-zero-days-in-ffmpeg
239•redbell•15h ago•157 comments

Launch HN: BitBoard (YC P25) – Analytics Workspace for Agents

https://bitboard.work/
48•arcb•20h ago•21 comments

H.R. 6028 would fundamentally change the U.S. Copyright Office

https://www.eff.org/deeplinks/2026/06/congress-just-rushed-through-disastrous-copyright-office-ov...
234•Cider9986•2d ago•86 comments

Shepherd's Dog: A Game by the Most Dangerous AI Model

https://koenvangilst.nl/lab/claude-fable-shepherds-dog
110•vnglst•7h ago•95 comments

Pirates, a naval warfare game inspired by Sid Meier's Pirates

https://piwodlaiwo.github.io/pirates/
287•iweczek•20h ago•82 comments

Israeli firm BlackCore suspected of meddling in New York and Scotland votes

https://www.reuters.com/world/israeli-firm-blackcore-also-suspected-meddling-nyc-scotland-votes-f...
275•pera•5h ago•139 comments

Show HN: Lightweight Task queue on Erlang/OTP, SQLite-backed, no overengineering

https://github.com/entGriff/ezra
50•ent1c3d•2d ago•9 comments

Automating Myself Out of Development

https://www.thoughtfultechnologist.com/p/automating-myself-out-of-development
45•nisabek•3d ago•25 comments

Tectonic: A modernized, complete, self-contained TeX/LaTeX engine

https://tectonic-typesetting.github.io/en-US/
67•maxloh•3d ago•32 comments

On CPU Physics and CPU Cycles

https://6it.dev/blog/on-cpu-physics-and-cpu-cycles-80730
54•signa11•8h ago•7 comments

Slightly reducing the sloppiness of AI generated front end

https://envs.net/~volpe/blog/posts/reduce-slop.html
207•FergusArgyll•22h ago•124 comments