Skip to content

Instantly share code, notes, and snippets.

@caveat-ops
Forked from Kidev/aur_check.sh
Last active June 13, 2026 15:35
Show Gist options
  • Select an option

  • Save caveat-ops/bfd78fe1f8e1ec7593e40c440297a18c to your computer and use it in GitHub Desktop.

Select an option

Save caveat-ops/bfd78fe1f8e1ec7593e40c440297a18c to your computer and use it in GitHub Desktop.
#!/usr/bin/env bash
#
# Check for AUR packages compromised in the 20260611 campaign
# Package list fetched live from: https://md.archlinux.org/s/SxbqukK6IA
LIST_URL="https://md.archlinux.org/s/SxbqukK6IA/download"
echo
echo "Fetching infected package list..."
mapfile -t INFECTED_PKGS < <(curl -fsSL "$LIST_URL" | tr -d '\r' | grep -E '^[a-zA-Z0-9]')
if [[ ${#INFECTED_PKGS[@]} -eq 0 ]]; then
echo "ERROR: Failed to fetch package list or list is empty."
exit 1
fi
echo "Checking for infected AUR packages (${#INFECTED_PKGS[@]} total)..."
echo
found=()
while read -r pkg; do
if LC_ALL=C pacman -Qi "$pkg" | tail -5 | head -1 | grep -qE 'Jun 9|Jun 10|Jun 11|Jun 12|Jun 13'; then
found+=("$pkg")
fi
done < <(pacman -Qmq "${INFECTED_PKGS[@]}" 2>/dev/null)
if [[ ${#found[@]} -eq 0 ]]; then
echo "Clean: None of the known infected packages were installed within the campaign window."
else
echo "WARNING: ${#found[@]} possibly infected package(s) found:"
for pkg in "${found[@]}"; do
echo " - $pkg"
done
fi
echo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment