GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    DarkMahesvara (darkmahesvara@varishangout.net)'s status on Saturday, 13-Jun-2026 14:56:11 JSTDarkMahesvaraDarkMahesvara
    https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/?noscript

    orphaned AUR packages got taken over to spread credential stealer malware in npm atomic lockfile. if you have not updated AUR in ~3 days or more you should be fine either way

    imperfect script to check for compromise:
    https://gist.github.com/Kidev/59bf9f5fb53ab5eee99f19a6a2fc3992

    echo "Affected Packages Found:"; comm -12 <(pacman -Qqm | sort) <(curl -s https://cscs.pastes.sh/raw/aurvulnlist20260611.txt | sort) | { read -r l && printf '%s\n' "$l" || echo "None. No known compromised packages are installed."; }

    find malicious file in AUR helper log:

    grep -r atomic-lockfile ~/.cache/yay
    grep -r atomic-lockfile ~/.cache/paru
    In conversationabout 2 months ago from varishangout.netpermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: lists.archlinux.org
      AUR REPORT THREAD - Aur-general - lists.archlinux.org
    2. Domain not in remote thumbnail source whitelist: github.githubassets.com
      aur_check.sh (OUTDATED, check https://gist.github.com/Kidev/85756c3dcad3623ca5604a8135bafd14)
      from Kidev
      aur_check.sh (OUTDATED, check https://gist.github.com/Kidev/85756c3dcad3623ca5604a8135bafd14)

    3. Invalid filename.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.