Nehmt Arch haben sie gesagt! Das wird toll, haben sie gesagt! ๐Ÿ™„

ScheiรŸ npm. Wer das erfunden hat, sollte sowieso ewig in die supply chain und dependency hell.

#arch #linux #aur #npm #supplychain #alvr

@sodiboo https://gaysex.cloud/notes/andaxow7itfn05x9

sodiboo :pride_heart: (@sodiboo)

MANY ORPHANED AUR PACKAGES ARE BEING TARGETED BY THE SAME INFOSTEALER. the Arch User Repository package `alvr` has been orphaned, then adopted by a threat actor who immediately updated it with an infostealer. If you have [this package](https://aur.archlinux.org/packages/alvr) on your system and updated it within the last 3 hours, you've been compromised. This is not a result of any upstream compromise; it's just that one AUR package. in particular, the `alvr-bin` sister package seems to be fine. [here's the relevant thread for `alvr` from the Arch Linux mailing list](https://lists.archlinux.org/archives/list/[email protected]/thread/2LGBF2AZBPVCCY4VTN6DOVUNNBURFJ2J/). SEVERAL OTHER PACKAGES ARE BEING TARGETED WITH THE SAME MALWARE: [1](https://lists.archlinux.org/archives/list/[email protected]/thread/L2JXQNYBGWOQQQXDEPEAICBHKFEFANUC/), [2](https://lists.archlinux.org/archives/list/[email protected]/thread/GNJEESAL6MT7LD2HCVP3HCTZIB6YQM2N/), [3](https://lists.archlinux.org/archives/list/[email protected]/thread/EAVGB55YBS4HRVU5N6NTYCGGMDDOJAM6/), [4](https://lists.archlinux.org/archives/list/[email protected]/thread/E5QPKBGL3QKLBOJ5HWUAS6AGZKHNTLG7/), [5](https://lists.archlinux.org/archives/list/[email protected]/thread/LVYB62N3FPAWUHNJ5Z5GXG6OIR7S5P3F/) [AUR mailing list megathread](https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/) they all share in common that they will install the `atomic-lockfile` package from NPM (that is [here's a live link to the actual malware](https://www.npmjs.com/package/atomic-lockfile). do not install that). they were all orphan takeovers. as far as i can tell, all of the ones i linked have been reverted to known safe versions. including `alvr`. this is an **infostealer**, meaning it exfiltrates sensitive data from your system such as login credentials. removing the malware will not undo the damage. moreover, **uninstalling the malicious package will not remove the malware** because it persists as a systemd service that stays on your system indefinitely. it executes as an npm preinstall script, and the npm package is installed by the AUR packages. this means that **simply installing the malicious versions of any of these packages will compromise you**. it does not require you to do anything more afterwards. again, **the malware persists if you uninstall the malicious packages** --- Attached is a screenshot of an announcement from the "Linux VR Adventures" discord. i know we all hate discord, but LVRA has a lot of auxiliary discussion, so [here's an invite link](https://discord.gg/zKPzbNwC6H) of special interest, [here's a malware analysis thread](https://discord.com/channels/1065291958328758352/1514675213089116342/1514675217056927774) that just started. Feel free to follow it in real time, or contribute, or whatever. (i've posted some details from that thread in the replies to this post) (๐Ÿ“Ž1)

sodiboo's shitposts

I used SteamVR with ALVR here on Bazzite linux but WiVRn with the latest XR-izer (edit: literally the most recent commit) finally plays the core set of games I like to play right now and it has passthrough capability by default so I can have my WayVR windows floating in real space. PLUS, almost biggest deal, is it runs like a dream. I maxed out my settings, resolution and FPS and MSFS2024 looks and feels GORGEOUS.

(I know all those things might sound made up but they're not lol)

One tip if on Fedora/Arch or similar is to install via the package manager for now because right now the flatpak has an outdated Mesa version included that causes graphical issues.

#VR #LinuxGaming #Steam #SteamVR #ALVR #WiVRn #XRizer #WayVR #MSFS2024  #Bazzite

The fun things you discover in #VRchat ๐Ÿ˜„ [#VisionOS #ALVR]

TIL: Depending if you are Playing Half-Life Alyx under linux with the native runtime or with proton, the savegame folder is
`%GAMEDATA%/game/hlvr/save` or `%GAMEDATA%/game/hlvr/SAVE`.
Which can lead to the situation, that the game thinks, you have no savegames at all (because case sensitive filesystem).

#halflife #halflifealyx #alyx #valve #vr #proton #linux #gaming #alvr #til

Okay, #ALVR is now working without compression artefacts. But the FPS could be better. Seems like I have to optimize more with the tons of settings.
And I have to figure out how to get BS Manager / #beatsaber running over ALVR and WiFi.
#VR on #linux is a nightmare. #alvr is nearly smooth, but image quality is really bad. #envision with #winvrn has great image quality, but only 40 FPS in #elitedangerous
anyone know why the heck this is happening to me in ALVR?

#Linux #LinuxGaming #VRChat #ALVR
@anthropy Could be good for #ValveIndex, but my experience with #Fedora, #Quest3S and #ALVR is baaaad. Maybe I'm doing something wrong, but I couldn't replicate even the performance of the original Meta app on #Windows (quite bad), let alone #VirtualDesktop (excellent), all on the same connection.
If you play #VR games on #Linux and use #ALVR for streaming, throw it away and use #WiVRN instead. It's just better. Ten thousand times better. #VideoGames

I tried SkyrimVR the first time since I left Windows behind, and whoa, I'm impressed! ๐Ÿคฉ Configuring it with the open sourcce ALVR launcher was more straightforward than with Meta's own app. The connection feels more error-proof too.

#gaming #gamingOnLinux #Skyrim #VR #OculusQuest2 #screenshot #Steam #alvr