-
-
Save caveat-ops/bfd78fe1f8e1ec7593e40c440297a18c to your computer and use it in GitHub Desktop.
aur_check.sh (OUTDATED, check https://gist.github.com/Kidev/85756c3dcad3623ca5604a8135bafd14)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #!/usr/bin/env bash | |
| # | |
| # Check for AUR packages compromised in the 20260611 campaign | |
| # Package list fetched live from: https://md.archlinux.org/s/SxbqukK6IA | |
| LIST_URL="https://md.archlinux.org/s/SxbqukK6IA/download" | |
| echo | |
| echo "Fetching infected package list..." | |
| mapfile -t INFECTED_PKGS < <(curl -fsSL "$LIST_URL" | tr -d '\r' | grep -E '^[a-zA-Z0-9]') | |
| if [[ ${#INFECTED_PKGS[@]} -eq 0 ]]; then | |
| echo "ERROR: Failed to fetch package list or list is empty." | |
| exit 1 | |
| fi | |
| echo "Checking for infected AUR packages (${#INFECTED_PKGS[@]} total)..." | |
| echo | |
| found=() | |
| while read -r pkg; do | |
| if LC_ALL=C pacman -Qi "$pkg" | tail -5 | head -1 | grep -qE 'Jun 9|Jun 10|Jun 11|Jun 12|Jun 13'; then | |
| found+=("$pkg") | |
| fi | |
| done < <(pacman -Qmq "${INFECTED_PKGS[@]}" 2>/dev/null) | |
| if [[ ${#found[@]} -eq 0 ]]; then | |
| echo "Clean: None of the known infected packages were installed within the campaign window." | |
| else | |
| echo "WARNING: ${#found[@]} possibly infected package(s) found:" | |
| for pkg in "${found[@]}"; do | |
| echo " - $pkg" | |
| done | |
| fi | |
| echo |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment