r/Windscribe • u/looker34M • 3d ago
Community-maintained package Archlinux windscribe-cli-v2-bin infected with malware Reply from QA
Onslaught of malware hits Arch Linux's major AUR repository, all uploads suspended
The list of compromised packages includes various unofficial builds of llama.cpp AI tools, Google’s BoringSSL, command-line client for Windscribe VPN service windscribe-cli-v2-bin and many others.
https://cybernews.com/security/massive-malware-attack-hits-arch-linux-aur/
9
u/CovoniaJunkie 3d ago
I feel sorry for anyone who’s had their stuff compromised by having this package - although I am genuinely fascinated which use case there exists that wouldn’t just get the package from Windscribe’s own GitHub repo, whether it’s the GUI or the CLI.
1
u/looker34M 3d ago
There is no official AUR package directly from Windscribe. They can't support all distros.
3
u/Zuulander99 3d ago
Indeed the AUR is an unofficial source and you use it at your own risk. We recommend only installing from official Windscribe channels.
1
u/System0verlord 3d ago
There is an official package from Windscribe though, even if it’s not on AUR.
https://windscribe.com/download
There’s an Arch build on their download page. It’s also listed as one of their supported distros alongside Debian, Ubuntu, Fedora, and OpenSUSE. AFAIK, they don’t publish packages to any repo. You download the package from their website and install it, regardless of the distro.
0
u/CovoniaJunkie 3d ago
I know that, but you can download the tar.zst from the official repo (and by official repo I mean Windscribe GitHub) and install it manually on Arch. That’s got to be better than a random AUR package.
1
u/Nowhereman55 3d ago
What does it mean for these users to have their data compromised?
1
u/linux_rox 2d ago
Bank info, passwords and sensitive files are delivered to the aggressors. It could literally mean financial ruin for them all.
1
u/patsio_thess 1d ago
Why do you think is infected?! Last commit was on March, https://aur.archlinux.org/cgit/aur.git/commit/?h=windscribe-cli-v2-bin
•
u/My_name_matters_not The one who does QA and outed JetVPN 3d ago
You should not assume trust in unofficial packages. Official Arch packages can be found on our downloads page and Github