{"adoption": {"forks": 53, "observed_at": "2026-08-28T04:06:21.516782+00:00", "stars": 2168}, "canonical_url": "https://ross.abutalabs.com/products/aur-malware-check", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Detection tools for the June 2026 atomic-lockfile AUR supply-chain attack. Consolidated from community Gists.", "domain": ["security", "developer-tools", "operating-systems"], "enriched": true, "function": ["security", "vulnerability-scanning", "cli", "developer-tools"], "health_score": 75, "homepage": null, "language": "Python", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["lenucksi/aur-malware-check"], "name": "lenucksi/aur-malware-check", "platform": ["python", "cli"], "pushed_at": "2026-07-07T17:16:17+00:00", "repo": "lenucksi/aur-malware-check", "stars": 2168, "tags": ["aur", "supply-chain-attack", "malware-detection", "arch-linux", "package-manager-security", "infostealer", "rootkit", "command-line", "linux"], "topics": [], "urls": [], "use_cases": ["check if my AUR packages are infected with atomic-lockfile malware", "scan my Arch system for the June 2026 AUR supply-chain attack", "detect compromised packages in npm, bun, yarn, and pnpm caches", "audit my system for eBPF rootkit and infostealer indicators", "refresh malware campaign package lists from upstream sources", "get JSON output of malware scan results for CI/CD pipelines", "track multiple AUR malware campaigns over time"], "what_it_is": "A Python CLI tool that detects compromised AUR packages from the June 2026 atomic-lockfile supply-chain attack and other historical campaigns. It scans installed packages, package caches, and system artifacts for indicators of compromise using a campaign-based configuration.", "when_to_avoid": ["you need real-time malware protection rather than point-in-time scanning", "you are not on Arch Linux or do not use the AUR", "you need a general-purpose antivirus rather than targeted supply-chain attack detection"], "when_to_choose": ["you use Arch Linux or an AUR helper and want to verify your system is clean", "you need a dependency-free, standard-library-only scanner you can run anywhere", "you want campaign-based detection that stays current with new attack waves", "you need machine-readable scan output for automation or CI"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/aur-malware-check", "repo": "lenucksi/aur-malware-check", "role": "main", "score": 54}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:06:21.516782+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:49:30.677065+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "8a2ef50b203874af8c555a7c393c7e2d8d5846ed5d62b6c44a95de827b466fa5", "fetched_at": "2026-08-28T04:06:21.516782+00:00", "kind": "readme", "missing": false, "url": "https://github.com/lenucksi/aur-malware-check"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 91, "longevity": 5, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "young"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 82, "days_push": 57, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 54, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}