Tools/lenucksi/aur-malware-check

aur-malware-check

Detection tools for the June 2026 atomic-lockfile AUR supply-chain attack. Consolidated from community Gists.

2.1k+22/wkemergingShellnew this week

The Lens

By Erik Loyd, SaaS CEO and former COO/CFO of an AWS Premier Partner.

Updated Jun 2026

aur-malware-check scans your Arch Linux system for traces of the June 2026 AUR supply-chain attack, the one that compromised over 1,600 packages in the Arch User Repository. It checks your installed packages against the known-bad lists and hunts for the attack's fingerprints: systemd persistence, eBPF rootkit traces, and poisoned npm and bun caches. The scripts are tuned to run in a second or two and return exit codes you can wire into automation.

There's nothing to host. You download the scripts and run them, and they tell you whether your machine shows signs of compromise. For a security tool this is about as low-friction as it gets, which matters when you need an answer fast and you're worried your box is already infected.

Arch users who installed AUR packages during the attack window are exactly who needs this, right now. If you don't run Arch or never touch the AUR, it's not for you. This is a targeted response to a specific incident, not a general antivirus, and that focus is its strength: it knows exactly what to look for.

The catch: it's incident-specific community scripts with no formal license and no warranty, the author says as much. A clean result is reassuring but not a guarantee, and a positive result means you've got real cleanup ahead. Use it as a fast first check, then verify anything it flags before you trust the machine again.

Free vs Self-Hosted vs Paid

fully free

Free tier: Free community security scripts. No paid version.

Self-hosted: You download and run the scripts locally. Free. No formal license.

Paid: None.

Free community scripts (no formal license, no warranty). A targeted incident response tool.

Self-hosting ops:trivial

Get tools like this every Wednesday

One featured tool, three on the radar. No fluff.

Score
57/100 · C+
Adoption16/30
Maintenance21/25
Community5/20
License5/15
Analysis10/10

A low score is not a verdict on quality. Young and niche tools start low by design. How we calculate scores

About

Owner
lenucksi (User)
Stars
2,051
Forks
47

Explore Further

More tools in the directory