• DonutsRMeh@lemmy.world
    link
    fedilink
    arrow-up
    37
    ·
    1 month ago

    I smell something fishy going on. I’ve been using the AUR for a long time and I’m now just hearing of malware?

    • Zikeji@programming.dev
      link
      fedilink
      English
      arrow-up
      53
      ·
      1 month ago

      There’s been malware in the past, not only that - AUR is user submitted. It’s in the name. They warn you to double check what you’re installing. It is functionally similar to running a random installer you found on GitHub.

      It seems like these instances are being intentionally blown out of proportion, but I don’t see what there is to gain by doing that.

      • kadu@lemmy.world
        link
        fedilink
        arrow-up
        40
        ·
        edit-2
        1 month ago

        It is functionally similar to running a random installer you found

        So basically how Windows users have been acquiring their software for the last 30 years.

      • DonutsRMeh@lemmy.world
        link
        fedilink
        arrow-up
        6
        ·
        1 month ago

        I don’t want to say stupid things, but I have so many theories. I check the shit out of a package before installing it. I even go to the GitHub page and make sure of things.

    • Shareni@programming.dev
      link
      fedilink
      arrow-up
      17
      ·
      1 month ago

      It’s an obvious vector for malware, arch by default doesn’t come with it, and users have been warned the entire time to check pkgbuild. There’s nothing fishy, it’s just that arch has enough users to be worth it to hit it.

    • storm@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      I expect that with SteamOS being based on Arch there will be a bigger target on Arch for malware just from increased attention on the platform