Security PSA for Arch users using certain AUR packages,
People using @arch must check if the following AUR packages are installed:
firefox-patch-bin,
librewolf-fix-bin,
zen-browser-patched-bin,
If any of these packages are present, remove them immediately and check for a process named systemd-initd.
What's going on,
A RAT (remote access trojan) has been discovered in the affected packages. This allows an attacker to remotely take over a system.
VirusTotal results of the malicious payload:
https://www.virustotal.com/gui/file/d9f0df8da6d66aaae024bdca26a228481049595279595e96d5ec615392430d67
The Arch maintainers have removed the offending AUR packages already; expect an official announcement from them soon.