54
[Tool] Privacy-focused AUR Malware Audit Tool (Atomic Arch Incident)
(the.unknown-universe.co.uk)
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
Even if you are not affected?
How do I know I'm not affected? I have to be fairly certain the packages identified are the only ones that were affected. That assesment could be wrong. If I 100% trust it, then yeah, I can trace if any of those packages/versions touched my machine. I would trust the package manager.
Here is an example with searxng-git: https://aur.archlinux.org/cgit/aur.git/log/?h=searxng-git
Look at the recent changes, inclusive the dates. The last change is from February. Let's open it: https://aur.archlinux.org/cgit/aur.git/commit/?h=searxng-git&id=24cc08c8aad50f5114db2d85251bde918b017cb8 with a description of "new ver":
Nothing has anything to do with the attack we experience right now. That is how you know that you are not affected by the current attack. Use scripts to check if you are attacked, and then lookup every single AUR package and verify yourself. If you can't be sure that you are under attack, then sure, reinstall and do not trust it. But if you can be sure, like I am, then you have nothing to worry. At least speaking of this specific attack.
In example if you don't use the AUR at all, or the packages you installed are not affected. In example the packages from the AUR I have installed have no such changes that could affect me from this malicious attack. Also if the packages you have are not updated in the last couple of days (or weeks) and are not even orphaned packages, then it is unlikely that you are affected by this attack. I am not talking of specific packages only, but a systematic logic you can follow.
The script https://github.com/lenucksi/aur-malware-check does a good job and not just check for known infected packages.