https://linuxmint.hu/hir/2025/08/ujabb-rosszindulatu-program-az-arch-aur-ban
Another Malware Found in Arch AUR
Another Malware Found in Arch AUR: Another Malicious Code Found in the Popular Package Repository
Just ten days after the previous incident, another malicious software was found among the Arch Linux AUR packages. This time, the attackers hid a Remote Access Trojan (RAT) in a seemingly harmless package disguised as a browser.
What exactly happened?
The AUR (Arch User Repository) is a collection of software created by the Arch Linux community and maintained by users, which many consider to be one of the greatest advantages of Arch, almost a “hidden treasure”. However, due to its completely open upload system, it can also become a target for malware.
After the previous incident ten days ago, a Remote Access Trojan (RAT) has now been added to the package repository. This time, the malicious code was hidden in a package called google-chrome-stable. The package not only installed the Google Chrome browser, but also used a Python script to download and run an external resource containing the malicious code every time it was started.
This type of malware can give attackers full access to the infected machine, allowing them to steal data, install additional malicious software, or even spy on it.
How did the package get uploaded?
The problematic package was uploaded by a newly registered user under the username “forsenontop”. In the PKGBUILD file, an install script (google-chrome-bin.install) called a launcher script (google-chrome-stable.sh) that ran a Python command with the -c option before Chrome was launched. This command pulled in an external resource on every launch, which downloaded the malware.
The good news is that the package was only available in the AUR for a few hours before it was detected and immediately removed by administrators. However, it still received a few upvotes, suggesting that several users may have already installed it.
What should affected users do?
If someone has installed the malicious package, they should immediately remove it and run a full security scan on their system. However, experts in the Arch community say that the safest solution is a full system reinstall (OS preinstall) to rule out any backdoors or hidden malicious code.
What’s the lesson?
This incident once again highlights that while the AUR is an extremely useful resource, the security of packages is not the responsibility of the official Arch Linux developers, but rather the community.
The incident clearly demonstrates how easy it is to upload a legitimate-looking package using a fake account. That’s why it’s important for users to always check the history of a package:
Check how long the package has been around.
Check the uploader’s reputation and the contents of the PKGBUILD file.
Avoid freshly uploaded packages with no history, even if the name seems official.
Browsers, as in the previous incident, are a particularly attractive target for attackers, as they are among the most widely used software.
Strengthen your future protection
Always check the PKGBUILD contents before installing:
yay -G packagename cd packagename less PKGBUILD
Avoid newly uploaded packages. If the AUR package has no history or reviews, it is not recommended to install it.
Another Malware Found in Arch AUR
Another Malware Found in Arch AUR: Another Malicious Code Found in the Popular Package Repository
Just ten days after the previous incident, another malicious software was found among the Arch Linux AUR packages. This time, the attackers hid a Remote Access Trojan (RAT) in a seemingly harmless package disguised as a browser.
What exactly happened?
The AUR (Arch User Repository) is a collection of software created by the Arch Linux community and maintained by users, which many consider to be one of the greatest advantages of Arch, almost a “hidden treasure”. However, due to its completely open upload system, it can also become a target for malware.
After the previous incident ten days ago, a Remote Access Trojan (RAT) has now been added to the package repository. This time, the malicious code was hidden in a package called google-chrome-stable. The package not only installed the Google Chrome browser, but also used a Python script to download and run an external resource containing the malicious code every time it was started.
This type of malware can give attackers full access to the infected machine, allowing them to steal data, install additional malicious software, or even spy on it.
How did the package get uploaded?
The problematic package was uploaded by a newly registered user under the username “forsenontop”. In the PKGBUILD file, an install script (google-chrome-bin.install) called a launcher script (google-chrome-stable.sh) that ran a Python command with the -c option before Chrome was launched. This command pulled in an external resource on every launch, which downloaded the malware.
The good news is that the package was only available in the AUR for a few hours before it was detected and immediately removed by administrators. However, it still received a few upvotes, suggesting that several users may have already installed it.
What should affected users do?
If someone has installed the malicious package, they should immediately remove it and run a full security scan on their system. However, experts in the Arch community say that the safest solution is a full system reinstall (OS preinstall) to rule out any backdoors or hidden malicious code.
What’s the lesson?
This incident once again highlights that while the AUR is an extremely useful resource, the security of packages is not the responsibility of the official Arch Linux developers, but rather the community.
The incident clearly demonstrates how easy it is to upload a legitimate-looking package using a fake account. That’s why it’s important for users to always check the history of a package:
Check how long the package has been around.
Check the uploader’s reputation and the contents of the PKGBUILD file.
Avoid freshly uploaded packages with no history, even if the name seems official.
Browsers, as in the previous incident, are a particularly attractive target for attackers, as they are among the most widely used software.
Strengthen your future protection
Always check the PKGBUILD contents before installing:
yay -G packagename cd packagename less PKGBUILD
Avoid newly uploaded packages. If the AUR package has no history or reviews, it is not recommended to install it.
🇺🇸 Trump deploys nuclear submarines because Medvedev was rude
Trump:
He's shitposting all the time … LMAO
🔗
➡️ Join us! | @MyLordBebo
Trump:
"Words are important and can lead to unintended consequences"
He's shitposting all the time … LMAO
🔗
➡️ Join us! | @MyLordBebo
Lindsey threatens to nuke, bomb and destroy a country once a week … he should sit down.
🔗
➡️ Join us! | @MyLordBebo
🔗
➡️ Join us! | @MyLordBebo
🇷🇺🇺🇸 The head of Roscosmos Bakanov and the acting head of NASA Duffy agreed to operate the ISS until 2028.
🔗
➡️ Join us! | @MyLordBebo
🔗
➡️ Join us! | @MyLordBebo
“NASA representatives discussed with their Roscosmos colleagues the possibility of rescuing each other's crews”
— NASA Deputy Administrator Kenneth Bowersox.
If a situation arises where a spacecraft from any country encounters a problem, and another country has a spacecraft available, they will be able to help each other.
🔗
➡️ Join us! | @MyLordBebo
#EU's new cybersecurity rules will impact #Android starting August 1, 2025. #Bootloader unlocking will likely be banned, limiting user control and custom ROM installations. #Samsung has already removed this feature in OneUI 8. A major shift for Android in Europe!"
https://xiaomitime.com/eu-kills-android-bootloader-unlock-starting-august-1-59449/
@xiaomiui
This is clickbait. There is no clause requiring to block bl unlock. There is stuff such as check to make sure updates are secure.
Samsung did remove it because they suck, but this wasn't a legal requirement.
https://xiaomitime.com/eu-kills-android-bootloader-unlock-starting-august-1-59449/
@xiaomiui
This is clickbait. There is no clause requiring to block bl unlock. There is stuff such as check to make sure updates are secure.
Samsung did remove it because they suck, but this wasn't a legal requirement.
XimiTime
Don’t panic: EU isn’t ending bootloader unlocks anytime soon - XimiTime
There’s been a significant amount of noise circulating online lately about the European Union’s Radio Equipment Directive (RED) and its supposed impact on
The AndroidFileHost was abandoned in 2023 and went offline a few weeks ago due to that a lot of Android development history, custom ROMs, kernels, gapps, etc. has been lost.
So, a reddit user has created AFHArchive, a site dedicated to preserving the files that were once hosted on AndroidFileHost. While uploading large files, just include as much info as you can, and after a review by the admins, they’ll be published for everyone to access again.
NOTE: AFHArchive is dedicated to preserving files that were previously hosted on AndroidFileHost.
• Only upload files that were once on AFH
• Provide original AFH links when possible
• Include device information & XDA threads
• All uploads require admin approval
• New builds or custom ROMs will not be approved
Follow @TechLeaksZone
So, a reddit user has created AFHArchive, a site dedicated to preserving the files that were once hosted on AndroidFileHost. While uploading large files, just include as much info as you can, and after a review by the admins, they’ll be published for everyone to access again.
NOTE: AFHArchive is dedicated to preserving files that were previously hosted on AndroidFileHost.
• Only upload files that were once on AFH
• Provide original AFH links when possible
• Include device information & XDA threads
• All uploads require admin approval
• New builds or custom ROMs will not be approved
Follow @TechLeaksZone
Reddit
From the androidroot community on Reddit
Explore this post and more from the androidroot community
Media is too big
VIEW IN TELEGRAM
Tucker Carlson: French President Emmanuel Macron is suing Candace Owens for claiming his wife was born a man. Candace joins us to present her evidence and explain why she’s looking forward to a legal battle.
(0:00) Brigitte Macron and the Lawsuit Against Candace
(12:06) The Origins of Candace’s Investigation Into the Macron Family
(25:17) The Disgusting Truth About Brigitte and Emmanuel Macron’s Relationship
(31:17) Why Are People Defending Sigmund Freud?
(43:57) The Demonic Book Featured in President Macron’s Official Portrait
(46:48) Why Candace Is Looking Forward to Trial
(56:30) Emmanuel Macron’s Mysterious Backstory
(1:01:01) Candace’s Interview With Nick Fuentes
(1:05:28) Does Fuentes Have Ulterior Motives?
(1:16:37) The Strange Attacks on “Christ Is King”
(1:19:41) The Deranged Babylon Bee Guy
(1:27:08) Candace’s Interview With Harvey Weinstein
(1:37:26) Was Michael Jackson Innocent?
(1:40:44) Why the Blake Lively Story Is Actually Important
(1:44:56) Candace’s Investigation Into the Epstein Case
(1:50:20) Morality, Truth, and Spiritual Warfare
(1:57:57) Candace Reflects on Her Time at The Daily Wire
(2:00:24) The Attempt on Candace’s Life
(2:01:38) Candace’s Advice to President Trump
(2:03:12) Candace’s Move to Catholicism
Includes paid partnerships.
(0:00) Brigitte Macron and the Lawsuit Against Candace
(12:06) The Origins of Candace’s Investigation Into the Macron Family
(25:17) The Disgusting Truth About Brigitte and Emmanuel Macron’s Relationship
(31:17) Why Are People Defending Sigmund Freud?
(43:57) The Demonic Book Featured in President Macron’s Official Portrait
(46:48) Why Candace Is Looking Forward to Trial
(56:30) Emmanuel Macron’s Mysterious Backstory
(1:01:01) Candace’s Interview With Nick Fuentes
(1:05:28) Does Fuentes Have Ulterior Motives?
(1:16:37) The Strange Attacks on “Christ Is King”
(1:19:41) The Deranged Babylon Bee Guy
(1:27:08) Candace’s Interview With Harvey Weinstein
(1:37:26) Was Michael Jackson Innocent?
(1:40:44) Why the Blake Lively Story Is Actually Important
(1:44:56) Candace’s Investigation Into the Epstein Case
(1:50:20) Morality, Truth, and Spiritual Warfare
(1:57:57) Candace Reflects on Her Time at The Daily Wire
(2:00:24) The Attempt on Candace’s Life
(2:01:38) Candace’s Advice to President Trump
(2:03:12) Candace’s Move to Catholicism
Includes paid partnerships.
Media is too big
VIEW IN TELEGRAM
Gavin Newsom’s $101M “Low-Income” Housing Project Exposed as Long-Term Real Estate Scam
Newsom's Pacific Palisades housing project isn’t about helping the homeless—it's a lucrative land grab for his real estate donors. The so-called “affordable” units come with covenants that expire in 15–25 years, converting the buildings to full market rate. By placing them in wealthy neighborhoods, the future value skyrockets—handing developers a 20x return. This isn’t public service—it’s pay-to-play corruption wrapped in a Democrat scam.
🇺🇸Join👉 @SGTnewsNetwork
📎 Twitter ▪️ Truth Social
Newsom's Pacific Palisades housing project isn’t about helping the homeless—it's a lucrative land grab for his real estate donors. The so-called “affordable” units come with covenants that expire in 15–25 years, converting the buildings to full market rate. By placing them in wealthy neighborhoods, the future value skyrockets—handing developers a 20x return. This isn’t public service—it’s pay-to-play corruption wrapped in a Democrat scam.
🇺🇸Join👉 @SGTnewsNetwork
📎 Twitter ▪️ Truth Social
Forwarded from Clash Report
Zeitenwende! Germany has now become a net electricity importer after shutting down its nuclear plants.
Forwarded from Vanessa Beeley
Post from journalist Hala Jaber on X - 1/2
The Two-State Solution is Dead.
What the world is offering Palestinians isn’t a state. The concept of a two-state solution for Israel and Palestine is often presented as a path to peace, but it has become an empty promise, a diplomatic illusion that distracts from the reality of occupation and apartheid. This thread examines why the two-state solution was & is no longer viable, analyzing its historical promises, current realities, & inherent flaws.
All this talk of a two-state solution is delusion at best, distraction at worst. Israel’s leadership has made it clear: it has no intention , ZERO, of allowing a sovereign Palestinian state, EVER. Even Netanyahu has said it:
“There is no post-war scenario that would lead to a Palestinian state.”
This collides with the idea of sovereignty. This stance reveals a fundamental contradiction: a “state” without sovereignty is not a state, it’s a rebranded occupation. Israel’s actions, settlement expansion, annexation policies, & daily violence, genocidal rhetoric, demonstrate that the system is designed to prevent Palestinian statehood, not enable it. It’s not a bug, it’s the system.
The rhetoric of a two-state solution persists as a diplomatic distraction, masking the reality of apartheid while offering Palestinians a hollow promise. So what are you negotiating? A mirage? A hostage with a flag isn’t a state? Stop dressing up apartheid as diplomacy.
Let’s assume, just for argument’s sake, a Palestinian state was declared tomorrow, its functionality would be impossible under current conditions. The proposed state would consist of two disconnected territories: Gaza in the southwest and the West Bank in the northeast, separated by a heavily militarized Israel. Israel controls all borders, airspace, and movement between these regions, rendering Palestinian autonomy dependent on Israeli permission.
A state without control over its borders, economy, or defense is not sovereign.
The Oslo framework demanded a demilitarized Palestine, leaving it defenseless against blockades, settler violence, or military incursions.
Even if Palestine were “recognized,” it would be a state in name only with:
No army. No control over borders, airspace, or economy. No right to defend itself. No protection from bombs, blockades, or settler militias.
This is not statehood, it’s an open-air prison with a flag & better branding.
But more importantly: it never acknowledged the Nakba:
The expulsion of 750,000 Palestinians, the theft of 78% of their homeland, the erasure of their right to return. Even the limited territory promised under Oslo II, Areas A and B, roughly 40% of the West Bank, has been eroded. Area C, comprising 60% of the West Bank, remains under full Israeli control. Over 700,000 Israeli settlers now live in 150 settlements and 128 outposts, most built post-Oslo, fragmenting the West Bank into disconnected enclaves. Settlement expansion and land theft have made a contiguous Palestinian state impossible.
What remains is a patchwork of cantons, surrounded by apartheid infrastructure, that cannot form the basis of a viable state. Instead, it asks Palestinians to accept symbolic scraps while their homeland is devoured & call it peace, when truth be told, that’s not reconciliation, it’s Western diplomacy laundering colonial dispossession.
This isn’t a “solution.” It’s a settlement of guilt, for everyone but Palestinians.
The two‑state model is a corpse: cold, buried, kept artificially warm by leaders who want to say they “tried.” But geography, justice, & reality have pronounced it dead. Symbolic gestures, like international recognition of a Palestinian state, are meaningless without control over land, resources, or security.
The Two-State Solution is Dead.
What the world is offering Palestinians isn’t a state. The concept of a two-state solution for Israel and Palestine is often presented as a path to peace, but it has become an empty promise, a diplomatic illusion that distracts from the reality of occupation and apartheid. This thread examines why the two-state solution was & is no longer viable, analyzing its historical promises, current realities, & inherent flaws.
All this talk of a two-state solution is delusion at best, distraction at worst. Israel’s leadership has made it clear: it has no intention , ZERO, of allowing a sovereign Palestinian state, EVER. Even Netanyahu has said it:
“There is no post-war scenario that would lead to a Palestinian state.”
This collides with the idea of sovereignty. This stance reveals a fundamental contradiction: a “state” without sovereignty is not a state, it’s a rebranded occupation. Israel’s actions, settlement expansion, annexation policies, & daily violence, genocidal rhetoric, demonstrate that the system is designed to prevent Palestinian statehood, not enable it. It’s not a bug, it’s the system.
The rhetoric of a two-state solution persists as a diplomatic distraction, masking the reality of apartheid while offering Palestinians a hollow promise. So what are you negotiating? A mirage? A hostage with a flag isn’t a state? Stop dressing up apartheid as diplomacy.
Let’s assume, just for argument’s sake, a Palestinian state was declared tomorrow, its functionality would be impossible under current conditions. The proposed state would consist of two disconnected territories: Gaza in the southwest and the West Bank in the northeast, separated by a heavily militarized Israel. Israel controls all borders, airspace, and movement between these regions, rendering Palestinian autonomy dependent on Israeli permission.
A state without control over its borders, economy, or defense is not sovereign.
The Oslo framework demanded a demilitarized Palestine, leaving it defenseless against blockades, settler violence, or military incursions.
Even if Palestine were “recognized,” it would be a state in name only with:
No army. No control over borders, airspace, or economy. No right to defend itself. No protection from bombs, blockades, or settler militias.
This is not statehood, it’s an open-air prison with a flag & better branding.
But more importantly: it never acknowledged the Nakba:
The expulsion of 750,000 Palestinians, the theft of 78% of their homeland, the erasure of their right to return. Even the limited territory promised under Oslo II, Areas A and B, roughly 40% of the West Bank, has been eroded. Area C, comprising 60% of the West Bank, remains under full Israeli control. Over 700,000 Israeli settlers now live in 150 settlements and 128 outposts, most built post-Oslo, fragmenting the West Bank into disconnected enclaves. Settlement expansion and land theft have made a contiguous Palestinian state impossible.
What remains is a patchwork of cantons, surrounded by apartheid infrastructure, that cannot form the basis of a viable state. Instead, it asks Palestinians to accept symbolic scraps while their homeland is devoured & call it peace, when truth be told, that’s not reconciliation, it’s Western diplomacy laundering colonial dispossession.
This isn’t a “solution.” It’s a settlement of guilt, for everyone but Palestinians.
The two‑state model is a corpse: cold, buried, kept artificially warm by leaders who want to say they “tried.” But geography, justice, & reality have pronounced it dead. Symbolic gestures, like international recognition of a Palestinian state, are meaningless without control over land, resources, or security.
Forwarded from Vanessa Beeley
2/2. The two-state solution has become a diplomatic prop, a way to maintain the appearance of progress while enabling occupation. Netenyahu’ statements including: “Any future independent Palestinian state would pose a threat to Israel’s existence,” further underscore the futility of negotiations. Recognition without sovereignty is publicity for occupation, not liberation.
Which brings us to today:
Western leaders are racing to “recognize” a Palestinian state; Starmer, Spain, Norway, framed as a historic gesture. But what are they actually offering? The current status quo: diminished land, no sovereignty, no protection. Even Netanyahu celebrates this in his statements, including in his July 2025 White House remarks that an independent Palestinian state would “pose a threat to Israel’s existence,” Recognition without sovereignty is publicity for occupation, not liberation.
Thread Summary:
The two-state solution is dead, if it was ever truly viable. It offers Palestinians neither sovereignty nor justice, serving instead as a distraction from the realities of occupation, displacement, and systemic violence.
Clinging to this outdated framework enables the status quo, not liberation. Palestinians deserve more than a flag over ruins or a seat at a table where their rights are perpetually deferred.
True peace requires confronting the root causes of injustice, the Nakba, land theft, and apartheid, and dismantling the systems that perpetuate them.
Anything less is not a solution; it’s a delusion dressed as diplomacy.
Recognition without justice isn’t peacekeeping. It’s betrayal, gift-wrapped, so let’s stop pretending this is statehood, it’s not. It’s PR over policy & fiction over freedom.
Follow Hala Jaber on X x.com/HalaJaber
Which brings us to today:
Western leaders are racing to “recognize” a Palestinian state; Starmer, Spain, Norway, framed as a historic gesture. But what are they actually offering? The current status quo: diminished land, no sovereignty, no protection. Even Netanyahu celebrates this in his statements, including in his July 2025 White House remarks that an independent Palestinian state would “pose a threat to Israel’s existence,” Recognition without sovereignty is publicity for occupation, not liberation.
Thread Summary:
The two-state solution is dead, if it was ever truly viable. It offers Palestinians neither sovereignty nor justice, serving instead as a distraction from the realities of occupation, displacement, and systemic violence.
Clinging to this outdated framework enables the status quo, not liberation. Palestinians deserve more than a flag over ruins or a seat at a table where their rights are perpetually deferred.
True peace requires confronting the root causes of injustice, the Nakba, land theft, and apartheid, and dismantling the systems that perpetuate them.
Anything less is not a solution; it’s a delusion dressed as diplomacy.
Recognition without justice isn’t peacekeeping. It’s betrayal, gift-wrapped, so let’s stop pretending this is statehood, it’s not. It’s PR over policy & fiction over freedom.
Follow Hala Jaber on X x.com/HalaJaber