For the record, those are all new packages (not orphaned packages being
adopted). I assume more will come, we’ll clean those as soon as possible.
In the mean time stay vigilant, probably refrain from installing freshly
pushed new packages from the AUR for now.
Looking over the list it’s almost all git/bin versions of files. So they just added a ton of new packages like hexchat-bin that didn’t have those versions before and injected malware.
I wonder why Aur is a target.
You think it’s Microsoft related?
Probably because it’s an attack vector where the effort required to infiltrate malware is relatively low.
From the mailing list thread:
Looking over the list it’s almost all git/bin versions of files. So they just added a ton of new packages like
hexchat-binthat didn’t have those versions before and injected malware.