Get the latest tech news

Arch Linux AUR Packages For Firefox & Other Browsers Removed For Containing Malware


While the Arch Linux AUR repository can be popular for fetching some packages not found in Arch Linux proper, it's important to keep in mind that AUR stands for the Arch User Repository

An Arch Linux user on Wednesday uploaded malicious AUR packages of firefox-patch-bin, librewolf-fix-bin, and zen-browser-patched-bin. Arch Linux administrators were made aware of these malicious packages and as of Friday they were removed. In any event a good public service announcement to remind users to exercise caution when relying on Arch Linux's AUR, Ubuntu PPAs, third-party Flatpaks / Snaps, and other user-contributed packages not always vetted by Linux distribution vendors.

Get the Android app

Or read this on Phoronix

Read more on:

Photo of malware

malware

Photo of Firefox

Firefox

Photo of browsers

browsers

Related news:

News photo

Arch Linux pulls AUR packages that installed Chaos RAT malware

News photo

Firefox-patch-bin, librewolf-fix-bin AUR packages contain malware

News photo

GitHub abused to distribute payloads on behalf of malware-as-a-service