
aur-malware-check
Detection tools for the June 2026 atomic-lockfile AUR supply-chain attack. Consolidated from community Gists.
The Lens
aur-malware-check scans your Arch Linux system for traces of the June 2026 AUR supply-chain attack, the one that compromised over 1,600 packages in the Arch User Repository. It checks your installed packages against the known-bad lists and hunts for the attack's fingerprints: systemd persistence, eBPF rootkit traces, and poisoned npm and bun caches. The scripts are tuned to run in a second or two and return exit codes you can wire into automation.
There's nothing to host. You download the scripts and run them, and they tell you whether your machine shows signs of compromise. For a security tool this is about as low-friction as it gets, which matters when you need an answer fast and you're worried your box is already infected.
Arch users who installed AUR packages during the attack window are exactly who needs this, right now. If you don't run Arch or never touch the AUR, it's not for you. This is a targeted response to a specific incident, not a general antivirus, and that focus is its strength: it knows exactly what to look for.
The catch: it's incident-specific community scripts with no formal license and no warranty, the author says as much. A clean result is reassuring but not a guarantee, and a positive result means you've got real cleanup ahead. Use it as a fast first check, then verify anything it flags before you trust the machine again.
Free vs Self-Hosted vs Paid
fully freeFree tier: Free community security scripts. No paid version.
Self-hosted: You download and run the scripts locally. Free. No formal license.
Paid: None.
Free community scripts (no formal license, no warranty). A targeted incident response tool.
Get tools like this every Wednesday
One featured tool, three on the radar. No fluff.
About
- Owner
- lenucksi (User)
- Stars
- 645
- Forks
- 17
Explore Further
More tools in the directory
openclaw
Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞
378.6k ★everything-claude-code
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
215.0k ★claw-code
The repo is finally unlocked. enjoy the party! The fastest repo in history to surpass 100K stars ⭐. Join Discord: https://discord.gg/5TUQKqFWd Built in Rust using oh-my-codex.
193.8k ★