At least on my system with fish shell it did not work out-of-the-box. When env provides another shell like “fish” isn’t fish used for execution?
No, the subshell used is the one on the hashbang line. That’s why people running zsh can still execute bash scripts like manjaro-chroot, update-grub, install-grub, et al. ![]()
It’s important to realize that the script runs in a subshell — i.e. a child process — not the interactive shell from which you invoke the script. ![]()
Also, I recommend not changing the shell referenced on the hashbang line, because the script was explicitly written to use bash, and fish may not be compatible with all of the internal shell commands in the script — I’ve never used fish, so I don’t know.
Thanks for the explanations. Probably the script did not start in my case for security reasons as the fish shell won’t search the current directory (by default) for an executable.
On the page where the script was taken from (linked at the beginning) there are also modifications for other shells you can try, after inspecting them.
The list keeps on growing — 1’579 infected packages as I’m posting this… ![]()
![]()
I think the most comprehensive script stays this one
Is constantly updated and currently includes indicators from many other forks if you run it with --full
Note that it uses database files in the repo so it is best to clone the repo with
git clone https://github.com/lenucksi/aur-malware-check.git
cd aur-malware-check
chmod +x aur_check-v2.sh
./aur_check-v2.sh --full
periodically update and run from its folder with
git pull
./aur_check-v2.sh --full --refresh -v
is this a AUR Problem or a github Problem ?
Aur, as written above. In github people published various scanning tools.
ok, thx @Teo
./aur_check-v2.sh --all-time
--- [1] Currently installed foreign packages ---
WARNING: 1 possibly infected package(s):
- wire-desktop (installed: Mon Jun 8 10:40:00 2026)
Looks like a false positive because after removal it comes out:
./aur_check-v2.sh --full
============================================================
AUR Malware Check v2.3.3
Campaign: malicious npm packages (malicious_npm_packages.txt) infostealer + eBPF rootkit
Date window: 2026-06-09 to 2026-06-12
Packages checked: 1619
============================================================
--- [1] Currently installed foreign packages ---
Clean: no infected packages installed within campaign window.
--- [2] Historical pacman logs ---
Clean: no historical log matches found.
--- [3] Systemd persistence check ---
Clean: no suspicious systemd services found.
--- [4] eBPF rootkit check ---
Clean: no eBPF rootkit traces detected.
--- [5] npm cache check ---
Clean: no malicious packages in npm cache.
--- [6] bun cache check ---
Clean: no malicious packages in bun cache.
============================================================
RESULT: CLEAN - No indicators found.
============================================================
I’d check the logic in that script. It doesn’t make sense that there is no historical match found if you had the package installed and uninstalled it. It should be recorded in your pacman logs.
Still shows with --all-time
# $ ./aur_check-v2.sh --all-time
# AUR Malware Check v2.3.3
Campaign: malicious npm packages (malicious_npm_packages.txt) infostealer + eBPF rootkit
Date window: all-time (no recency filter)
Packages checked: 1619
— \[1\] Currently installed foreign packages —
Clean: no infected packages currently installed.
— \[2\] Historical pacman logs —
LOG_HIT: wineasio-git (installed on 2019-12-31)
LOG_HIT: python2-appdirs (installed on 2020-01-10)
LOG_HIT: python2-pyparsing (installed on 2020-01-10)
LOG_HIT: python2-packaging (installed on 2020-01-10)
LOG_HIT: python2-chardet (installed on 2020-01-10)
LOG_HIT: python2-cssselect (installed on 2020-01-10)
LOG_HIT: python2-packaging (upgraded on 2020-01-16)
LOG_HIT: beebeep (installed on 2020-01-16)
LOG_HIT: python2-packaging (upgraded on 2020-02-28)
LOG_HIT: python2-packaging (upgraded on 2020-03-19)
LOG_HIT: vidcutter (installed on 2020-03-23)
LOG_HIT: python2-packaging (upgraded on 2020-03-24)
LOG_HIT: python2-pyparsing (upgraded on 2020-04-08)
LOG_HIT: beebeep (upgraded on 2020-04-30)
LOG_HIT: python2-appdirs (upgraded on 2020-06-01)
LOG_HIT: python2-packaging (upgraded on 2020-06-01)
LOG_HIT: python2-chardet (upgraded on 2020-06-01)
LOG_HIT: python2-cssselect (upgraded on 2020-06-01)
LOG_HIT: vidcutter (upgraded on 2020-07-22)
LOG_HIT: libgdata (installed on 2020-09-25)
LOG_HIT: libgdata (upgraded on 2020-11-05)
LOG_HIT: wire-desktop (installed on 2020-11-14)
LOG_HIT: python2-appdirs (upgraded on 2020-12-31)
LOG_HIT: python2-pyparsing (upgraded on 2020-12-31)
LOG_HIT: python2-packaging (upgraded on 2020-12-31)
LOG_HIT: wire-desktop (upgraded on 2020-12-31)
LOG_HIT: python2-packaging (upgraded on 2021-01-19)
LOG_HIT: guiscrcpy (installed on 2021-01-21)
LOG_HIT: python2-packaging (upgraded on 2021-02-19)
LOG_HIT: libgdata (upgraded on 2021-02-28)
LOG_HIT: wire-desktop (upgraded on 2021-03-19)
LOG_HIT: wire-desktop (upgraded on 2021-04-09)
LOG_HIT: wire-desktop (upgraded on 2021-05-19)
LOG_HIT: wire-desktop (upgraded on 2021-08-22)
LOG_HIT: python2-packaging (upgraded on 2021-09-16)
LOG_HIT: python2-appdirs (upgraded on 2022-01-02)
LOG_HIT: python2-pyparsing (upgraded on 2022-01-02)
LOG_HIT: python2-packaging (upgraded on 2022-01-02)
LOG_HIT: wire-desktop (upgraded on 2022-02-27)
LOG_HIT: wire-desktop (upgraded on 2022-05-13)
LOG_HIT: vidcutter (installed on 2022-06-27)
LOG_HIT: wire-desktop (upgraded on 2022-08-07)
LOG_HIT: python-future (installed on 2022-08-13)
LOG_HIT: wire-desktop (upgraded on 2022-11-08)
LOG_HIT: vidcutter (upgraded on 2022-12-06)
LOG_HIT: wire-desktop (upgraded on 2022-12-24)
LOG_HIT: wire-desktop (upgraded on 2023-01-24)
LOG_HIT: vidcutter (upgraded on 2023-02-03)
LOG_HIT: vidcutter (upgraded on 2023-06-04)
LOG_HIT: wire-desktop (upgraded on 2023-07-10)
LOG_HIT: wire-desktop (upgraded on 2023-10-13)
LOG_HIT: wire-desktop (upgraded on 2024-05-13)
LOG_HIT: wire-desktop (upgraded on 2024-05-29)
LOG_HIT: wire-desktop (upgraded on 2024-06-11)
LOG_HIT: wire-desktop (reinstalled on 2024-08-20)
LOG_HIT: wire-desktop (installed on 2024-08-20)
LOG_HIT: wire-desktop (upgraded on 2024-09-02)
LOG_HIT: wire-desktop (upgraded on 2024-12-02)
LOG_HIT: wire-desktop (upgraded on 2024-12-16)
LOG_HIT: wire-desktop (upgraded on 2025-02-05)
LOG_HIT: wire-desktop (upgraded on 2025-05-06)
LOG_HIT: manuskript (installed on 2025-05-24)
LOG_HIT: wire-desktop (upgraded on 2025-12-25)
LOG_HIT: coolreader (installed on 2026-01-21)
LOG_HIT: wire-desktop (installed on 2026-06-05)
LOG_HIT: wire-desktop (installed on 2026-06-08)
WARNING: historical log matches:
* wineasio-git (installed on 2019-12-31)
* python2-appdirs (installed on 2020-01-10)
* python2-pyparsing (installed on 2020-01-10)
* python2-packaging (installed on 2020-01-10)
* python2-chardet (installed on 2020-01-10)
* python2-cssselect (installed on 2020-01-10)
* python2-packaging (upgraded on 2020-01-16)
* beebeep (installed on 2020-01-16)
* python2-packaging (upgraded on 2020-02-28)
* python2-packaging (upgraded on 2020-03-19)
* vidcutter (installed on 2020-03-23)
* python2-packaging (upgraded on 2020-03-24)
* python2-pyparsing (upgraded on 2020-04-08)
* beebeep (upgraded on 2020-04-30)
* python2-appdirs (upgraded on 2020-06-01)
* python2-packaging (upgraded on 2020-06-01)
* python2-chardet (upgraded on 2020-06-01)
* python2-cssselect (upgraded on 2020-06-01)
* vidcutter (upgraded on 2020-07-22)
* libgdata (installed on 2020-09-25)
* libgdata (upgraded on 2020-11-05)
* wire-desktop (installed on 2020-11-14)
* python2-appdirs (upgraded on 2020-12-31)
* python2-pyparsing (upgraded on 2020-12-31)
* python2-packaging (upgraded on 2020-12-31)
* wire-desktop (upgraded on 2020-12-31)
* python2-packaging (upgraded on 2021-01-19)
* guiscrcpy (installed on 2021-01-21)
* python2-packaging (upgraded on 2021-02-19)
* libgdata (upgraded on 2021-02-28)
* wire-desktop (upgraded on 2021-03-19)
* wire-desktop (upgraded on 2021-04-09)
* wire-desktop (upgraded on 2021-05-19)
* wire-desktop (upgraded on 2021-08-22)
* python2-packaging (upgraded on 2021-09-16)
* python2-appdirs (upgraded on 2022-01-02)
* python2-pyparsing (upgraded on 2022-01-02)
* python2-packaging (upgraded on 2022-01-02)
* wire-desktop (upgraded on 2022-02-27)
* wire-desktop (upgraded on 2022-05-13)
* vidcutter (installed on 2022-06-27)
* wire-desktop (upgraded on 2022-08-07)
* python-future (installed on 2022-08-13)
* wire-desktop (upgraded on 2022-11-08)
* vidcutter (upgraded on 2022-12-06)
* wire-desktop (upgraded on 2022-12-24)
* wire-desktop (upgraded on 2023-01-24)
* vidcutter (upgraded on 2023-02-03)
* vidcutter (upgraded on 2023-06-04)
* wire-desktop (upgraded on 2023-07-10)
* wire-desktop (upgraded on 2023-10-13)
* wire-desktop (upgraded on 2024-05-13)
* wire-desktop (upgraded on 2024-05-29)
* wire-desktop (upgraded on 2024-06-11)
* wire-desktop (reinstalled on 2024-08-20)
* wire-desktop (installed on 2024-08-20)
* wire-desktop (upgraded on 2024-09-02)
* wire-desktop (upgraded on 2024-12-02)
* wire-desktop (upgraded on 2024-12-16)
* wire-desktop (upgraded on 2025-02-05)
* wire-desktop (upgraded on 2025-05-06)
* manuskript (installed on 2025-05-24)
* wire-desktop (upgraded on 2025-12-25)
* coolreader (installed on 2026-01-21)
* wire-desktop (installed on 2026-06-05)
* wire-desktop (installed on 2026-06-08)
# ============================================================
RESULT: INFECTED - Indicators found! Follow incident response.
It’s frustrating that there’s a lot of basic information that’s hard to find. I have a package from the list, but it was last updated in 2024. So… when did this hack actually start?
Is there a list of hacked package that includes versions?
If I don’t have bun or npm installed am I safe?
Is there a simple test to look for files installed or changed by the hack?
How hard does the hack work to hide itself? Do I need to boot from a thumb drive to ensure I’m getting accurate test results?
There’s multiple check scripts out there. Some of them seem dumb (you have a package that might be compromised). How do I know which check script is the most up to date and trustworthy?
Is there a single location I can go for answers that is reliably consolidating all of this sort of information?
Ahh, I see what you did there. Ran the initial run with --all-time then the second run after removal with --full which don’t give the same results. So your comment:
is misleading because it wasn’t the removal that caused the package to not show but the option you used to run the script.
I’d still manually inspect the build files for wire-desktop since it was installed a day before the known campaign window.
The big question is with the timeframe. Some scripts put the time filtering as far as 1 Jan 2026. (The full time option). This seems to be a bit too much. In my tests it showed me 2 packages i had later uninstalled, one of them vidcutter. Going to the aur page and checking the diff in the historical log, the april version was clean, it was only a version bump from the source.
So i tend to think the infection timeframe was smaller. In the last script i posted the default timeframe (if you do not use --full-time) is set to 9-12 Jun 26. And this script consolidates a lot of other scripts with checking for at least 5 infection indicators if you run with --full. It is also constantly updated (last time 4 hours before i posted).
The attack was pretty sofisticated so more info is comming out with time. There is no ultimative, exsaustive list of files to check and be sure, because the thing was hidden under many layers. That just shows how ineffective signature based antiviruses are nowadays. In theory there are hashes of two binsries but they were only temporary present.
There’s also Forkgram - I used it for a year now and completely forgot that I don’t have Telegram installed until this post came up.
📦 Name: forkgram-bin
🌐 Upstream URL: https://github.com/Forkgram/tdesktop
👍 Votes: 6
📈 Popularity: 0.86
🧩 Version: 6.9.1-1
💾 Size: 0 B
📝 Description: Forkgram is the fork of the official Telegram Desktop application - Static binary
📅 First Submitted: 2021-10-07 22:52:31 (UTC)
🕒 Last Updated: 2026-06-10 18:10:25 (UTC)
🔗 Link: https://aur.archlinux.org/packages/forkgram-bin
This also is completely unaffected by the current AUR fiasco, I’ve been very careful to vet my updates.
You can also get a current status with a script:
curl -s https://cscs.pastes.sh/raw/aurvulntest20260611.sh | bash
Having traur installed will also flag up:
- Executing cod in-line in the PKGBUILD
- Installing dangerous system hooks
- Low user votes
- use of curl
Traur would likely flag the injection of npm or bun into a package that shouldn’t need JavaScript tools.
The attack also focused on orphaned packages, with very few votes or comments - which is something Traur does pick up on.
Whilst “popular” might be attractive to an attacker that doesn’t seem to be how things happened in this scenario. It seems abandoned/orphaned packages were adopted by the attackers; thus original owner maintained packages should be safe. Obviously one should be more careful and double check the maintainer and any recent changes, and inspect the build files - but really this should be common practice for packages from the AUR at any time.
The problem here was the malicious actor managed to impersonate and upload updates from the name of a legit developer. Besides the other 5 accounts that were used.
@Ben this is a rather static and simple version of a checking script, there are way more advanced versions now.
Ah, yes - this one, for example, which pulls in lists of discovered breaches from several sources (like CSCS and others)…
Latest update Sat Jun 13 2026 21:52:34 GMT+0000 - 1935 packages
$ check-aur-infected.sh
Fetching infected package list from https://md.archlinux.org/s/SxbqukK6IA...
Checking for infected AUR packages (1935 total)...