Nemeski@mander.xyz to Linux@programming.dev · 3 months agoActive AUR malicious packages incidentarchlinux.orgexternal-linkmessage-square26linkfedilinkarrow-up1100arrow-down10
arrow-up1100arrow-down1external-linkActive AUR malicious packages incidentarchlinux.orgNemeski@mander.xyz to Linux@programming.dev · 3 months agomessage-square26linkfedilink
minus-squareEquinox1289@sh.itjust.workslinkfedilinkarrow-up8arrow-down2·3 months agoThis is why I prefer Flatpaks, or really any application sandboxing.
minus-square9tr6gyp3@lemmy.worldlinkfedilinkEnglisharrow-up6·3 months agoAUR packages can be sandboxed with many different solutions. Any pckage can be sandboxed really.
minus-squareDefault Username@lemmy.dbzer0.comlinkfedilinkEnglisharrow-up9·3 months agoThis attack was executed by a script running in the PKGBUILD itself. You didn’t have to run the application to be infected since just building it will infect your machine.
minus-square9tr6gyp3@lemmy.worldlinkfedilinkEnglisharrow-up3·3 months agoYeah, I bet the build process could also be sandboxed, but Im sure its not the default.
minus-squareDefault Username@lemmy.dbzer0.comlinkfedilinkEnglisharrow-up4·3 months agoSandboxing the build process would be a process. Nix already does it, for example. Many AUR packages don’t include a full list of dependencies.
minus-squarepatlefort@lemmy.worldlinkfedilinkarrow-up2·3 months agoIt also had an install script that will be run as root when the package is installed. Can’t sandbox that.
This is why I prefer Flatpaks, or really any application sandboxing.
AUR packages can be sandboxed with many different solutions. Any pckage can be sandboxed really.
This attack was executed by a script running in the PKGBUILD itself. You didn’t have to run the application to be infected since just building it will infect your machine.
Yeah, I bet the build process could also be sandboxed, but Im sure its not the default.
Sandboxing the build process would be a process. Nix already does it, for example. Many AUR packages don’t include a full list of dependencies.
It also had an install script that will be run as root when the package is installed. Can’t sandbox that.