24 Followers
373 Following
461 Posts

Everything in FOSS that isn't code.
#isolveproblems #thisisreallygoodcoffee

Sat on the Berlin wall the day it fell. From the walled in side. Sat on an Ambulance roof the day the bells rang.

MANY ORPHANED AUR PACKAGES ARE BEING TARGETED WITH AN INFOSTEALER. official statement (fediverse discussion)

collection of detection scripts

the Arch User Repository package
alvr has been orphaned, then adopted by a threat actor who immediately updated it with an infostealer. If you have this package on your system and updated it recently, you've been compromised. This is not a result of any upstream compromise; it's just that one AUR package. in particular, the alvr-bin sister package seems to be fine.

here's the relevant thread for alvr from the Arch Linux mailing list. alvr seems to be the first package compromised and/or the first one that was noticed. it was updated maliciously at 2026-06-11 13:53:45 UTC (2026-06-11T13:53:45.000Z) and reverted approximately 3-4 hours after that.

SEVERAL OTHER PACKAGES ARE BEING TARGETED WITH THE SAME MALWARE:
1, 2, 3, 4, 5

AUR mailing list megathread <-- over 400 (!!!!) packages have the malicious npm dependency

i believe this is an up-to-date list of all packages that are known to be compromised

they all share in common that they will install the
atomic-lockfile package from NPM. they were all orphan takeovers. as far as i can tell, all of the ones that have been noticed were reverted to known safe versions. including alvr.

THAT NPM PACKAGE HAS BEEN TAKEN DOWN, but there is another wave of this attack still ongoing! this time, the infected packages are installing
js-digest or lockfile-js, also from npm registry (but using bun). js-digest was already taken down, but lockfile-js was published 2026-06-12 13:01:03 UTC (2026-06-12T13:01:03.000Z) and is still live right now !!

this is an
infostealer, meaning it exfiltrates sensitive data from your system such as browser cookies, discord tokens, ssh keys, and container registry logins. removing the malware will not undo the damage; the attacker now has all your credentials. moreover, uninstalling the malicious package will not remove the malware because it persists as a systemd service that stays on your system indefinitely.

it executes as an npm preinstall script, and the npm package is installed by the AUR packages. this means that
simply installing the malicious versions of any of these packages will compromise you. it does not require you to do anything more afterwards. again, the malware persists if you uninstall the malicious packages

to check if you've been compromised, look in
/etc/systemd/system and ~/.config/systemd/user for a recently added .service file with a random name. that's the persistence mechanism and the most obvious mark that you've been compromised.

---

Attached is a screenshot of an announcement from the "Linux VR Adventures" discord.

i know we all hate discord, but LVRA has a lot of auxiliary discussion, so
here's an invite link. (or at least, it had a lot of relevant discussion when the news broke and this post was much shorter; it's mostly quiet now as we realized the scope goes way beyond VR. this post is also now more complete than it was)

of special interest,
here's a malware analysis thread. Feel free to follow it in real time, or contribute, or whatever. Whanos has produced a preliminary analysis blog post that contains a lot of important information about the malware.

400+ Arch User Repository packages have been compromised in a massive, sophisticated supply chain attack, including a rootkit installation.

https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577

#ThreatIntel #ThreatIntelligence #IFIN

400+ AUR Packages Compromised with Infostealer and Rootkit

Last Updated: 2026-06-12T04:22:42Z (UTC) What’s Happening It appears an AUR package maintainer’s account (arojas) was compromised. The maintainer’s account had write access to over 400 package repos. The compromise was reported and other AUR maintainers have been working to remove the infected packages. The affected packages were modified with preinstall scripts to use npm to install the atomic-lockfile package, a malicious payload. Here’s an example of the change: This blog has a deep d...

IFIN

Heute in "ja genau, das wird die erhoffte Schadenspräventionswirkung bringen":

https://www.heise.de/news/Fable-5-blockiert-auch-sicheren-Code-11328448.html

Sicher, Guardrails sind wichtig. Wenn allerdings der durchschnittliche Claude-Nutzer dann endlich mal auf die Idee kommt vielleicht nach defensive / sicherem Code zu fragen oder nach einer Durchsicht & Cleanup für den Moloch in seinem Repo zu fragen und ein 'Computer says no' hört, dann wird das sicher nicht zur Motivation beitragen.
Wohl eher zur aktiven Einfügung von Formulierungen die diese dann als "Arbeitsblockierer" wahrgenommenen Guard Rails aktiv nicht triggern wie "bloß nicht nach sicherem Code fragen".

Kombiniert mit Geschwindigkeit und Volumen der Code Produktion durch Claude & Co ist der Effekt durch aktiv rottigen Code wohl schnell größer als der Effekt der Abwehr der üblichen low(er)-level Kriminellen, Skriptkiddies und Co gebracht hätte. Und ich würde annehmen, dass jeder Akteur mit ausreichender krimineller Energie und Mitteln ohnehin andere Werkzeuge und Zugriffsmöglichkeiten hat um Schaden auf diesem Wege anzurichten.

Abgesehen davon: Wann einmal alle üblichen OWASP10 + defensive Coding Regeln im Claude Code System Prompt? 😆

#claudecode #ai #ClaudeMythos5 #mythosaimodel #fable #Anthropic #owasp #OWASPTopTen #harmreduction #hottake

Fable 5 blockiert auch sicheren Code

Schon das Stichwort „Security Audit“ reicht: Forscher kritisieren Anthropics Fable 5, weil dessen Cybersecurity-Filter auch harmlose Anfragen ausbremsen.

heise online
Warum Leute abblocken benutzen... die Box in der Mitte ist der Content
How it started vs how it’s going.

Fundstück des Tages: https://www.messenger-matrix.de/messenger-matrix-en.html

Inhaltlich jetzt nicht üiberprüft aber sicher eine gute Aufbereitung vom visuellen und den Kategorien-mäßig auf den ersten Blick

#messenger #chat #instantmessaging #xmpp #deltachat #signalapp

Messenger-Matrix • Kuketz IT-Security Blog

Messenger: Comparison of security- and data protection-relevant features of messengers

Folks. I just had the very first #XMPP Space Call 😸!

There are still a couple of things to iron out, but you can now make conference calls in XMPP Spaces! ✨

After 15 years of work on #Movim , countless commits, improvements, and refactoring, I am incredibly proud to offer everyone a fully standard, lightweight, and open-source alternative to major platforms like #Discord, Microsoft Teams, and Slack.

There are a few minor things left to standardize, but you can already build another client that fully integrates with Movim.

On the XMPP server side, everything is already in place. 👌

If you'd like to help me continue this journey: https://movim.eu/#fund 🫶

You use #Fedora 44 and #Gnome, and paste via middle mouse button won't work anymore? Well, this is an intentional design decision by the @gnome devs. They've changed the default.

To restore it:

gsettings set org.gnome.desktop.interface gtk-enable-primary-paste true

EDIT: You can also use the Gnome Tweak Tools to change the setting.

See: https://bugzilla.redhat.com/show_bug.cgi?id=2466940

#Fedora44

2466940 – mouse selection as copy and middle click as paste no longer work

Error: password must contain:

Three lower case letters for the Elven-kings under the sky,
Seven upper case letters for the Dwarf-lords in their halls of stone,
Nine digits for Mortal Men doomed to die,
One special character for the Dark Lord on his dark throne;
In the Land of Mordor where the Shadows lie.

One username to rule them all, one password to find them,
A second factor to bring them all, and in the darkness bind them;
In the Land of Mordor where the Shadows lie