Uploaded July 2026 | Updated September 2026, 2 weeks ago
reddit.com/r/archlinux/comments/1vaxtcs/another_wave_200_malicous_aur_packages_adoptions/?share_id=l4BDZpYrhNW0LPoGag1eD
rumble.com/user/MattsCreative1909
NEW DISCORD: discord.gg/u4aEzNnhTg
YouTube Members
youtube.com/channel/UCzoVL1aVjec7YKPeG59xKFg/join
• Ko-fi
ko-fi.com/tlv
• PayPal
paypal.me/gamedev1909
• SYSTEM SPECS
• OS: PikaOS
• Desktop: Hyprland
• CPU: Ryzen 9 9900X (5.6GHz)
• Memory: 64 GiB DDR5 6000MHz
• Storage: 22TB
• GPU: RTX 5070TI
0:00 – Intro and moving to Picos/Fedora issues.
1:04 – Personal experience with hacking and protection is necessary.
2:12 – How Discord alt accounts and Raspberry Pies are used for logging.
3:09 – The problem with Arch and the AUR safety model.
3:33 – Thoughts on replacing the AUR and fixing duplications.
4:28 – Success with video editing/rendering on an APU laptop.
5:13 – Details on the July 30th, 2026, AUR malware campaign.
6:37 – Explaining what the AUR is and its "killer feature" flaws.
7:26 – Critical security flaws: Adopted abandoned packages and lack of moderation.
8:14 – Proposed solutions: GitHub linking, verification, and removal of abandoned packages.
10:09 – Breakdown of the July 2026 attack: Adoption, injection, and spoofing metadata.
12:11 – The payload: How the malware uses Tor, second-stage retrieval, and credential theft.
14:22 – Security measures beyond passwords (PINs, passphrases, and passkeys).
15:05 – List of the first, second, and third batches of compromised packages.
16:19 – Advice for affected users: Backups, drive wiping, and password management.
17:05 – Recommendations for alternative distributions (Picos, Fedora). #dreamy
reddit.com/r/archlinux/comments/1vaxtcs/another_wave_200_malicous_aur_packages_adoptions/?share_id=l4BDZpYrhNW0LPoGag1eD
rumble.com/user/MattsCreative1909
NEW DISCORD: discord.gg/u4aEzNnhTg
YouTube Members
youtube.com/channel/UCzoVL1aVjec7YKPeG59xKFg/join
• Ko-fi
ko-fi.com/tlv
• PayPal
paypal.me/gamedev1909
• SYSTEM SPECS
• OS: PikaOS
• Desktop: Hyprland
• CPU: Ryzen 9 9900X (5.6GHz)
• Memory: 64 GiB DDR5 6000MHz
• Storage: 22TB
• GPU: RTX 5070TI
0:00 – Intro and moving to Picos/Fedora issues.
1:04 – Personal experience with hacking and protection is necessary.
2:12 – How Discord alt accounts and Raspberry Pies are used for logging.
3:09 – The problem with Arch and the AUR safety model.
3:33 – Thoughts on replacing the AUR and fixing duplications.
4:28 – Success with video editing/rendering on an APU laptop.
5:13 – Details on the July 30th, 2026, AUR malware campaign.
6:37 – Explaining what the AUR is and its "killer feature" flaws.
7:26 – Critical security flaws: Adopted abandoned packages and lack of moderation.
8:14 – Proposed solutions: GitHub linking, verification, and removal of abandoned packages.
10:09 – Breakdown of the July 2026 attack: Adoption, injection, and spoofing metadata.
12:11 – The payload: How the malware uses Tor, second-stage retrieval, and credential theft.
14:22 – Security measures beyond passwords (PINs, passphrases, and passkeys).
15:05 – List of the first, second, and third batches of compromised packages.
16:19 – Advice for affected users: Backups, drive wiping, and password management.
17:05 – Recommendations for alternative distributions (Picos, Fedora). #dreamy










