More than 70 packages in the Arch Linux User Repository have been compromised by unauthorized commits that inject Russian spam and offensive messages into user shell configuration files.
Key Points
- Over 70 AUR packages, including Llama.cpp and various Python and Ruby tools, were modified to include malicious shell scripts.
- The unauthorized commits occurred on October 14, shortly after a separate incident involving 1,500 malware-laden packages.
- Security researcher Nicolas Boichat identified the spam using an AI-based detection bot designed to monitor repository content.
- The injected code targets common shell configuration files, specifically bashrc, zshrc, and Fish, to display offensive messaging.