Skip to content

Instantly share code, notes, and snippets.

View real-or-random's full-sized avatar
🌴
On vacation

Tim Ruffing real-or-random

🌴
On vacation
View GitHub Profile
@l33tm4st3r
l33tm4st3r / aur_malware_check.sh
Last active June 17, 2026 07:12
AUR supply-chain malware checker (atomic-lockfile / lockfile-js / nextfile-js campaign, June 2026) - behavior-based detection
#!/usr/bin/env bash
#
# aur_malware_check.sh - official-list + BEHAVIOR-based detection
#
# AUR malware campaign, June 2026
# (atomic-lockfile / lockfile-js / nextfile-js / js-digest):
# https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/
#
# Two complementary strategies:
# - Cross-check installed AUR packages against Arch's authoritative live list.
@toolmantim
toolmantim / 01-extract-commit-and-sig.sh
Created September 7, 2016 00:57
How to manually verify a signed git commit with GPG. This assumes you have GPG installed, and you have the public key added to the default keyring.
$ git cat-file -p 1b51f44d6b1e6c6eff3302a4af5a2b983a5d2161
tree fc069c67c550c449ff001fec804ad98c04c128da
parent bf17d1df5061aa67e4647fa3f7f3abd2cbe045ee
author Tim Lucas <t@toolmantim.com> 1473126017 +1000
committer Tim Lucas <t@toolmantim.com> 1473126017 +1000
gpgsig -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAABAgAGBQJXzh6fAAoJEEWaob2jtb+GzVEQAIDh2MFyF90ui00/hssG2ehW
cKImqo5VvDmv+j9oo+QL5MiH4Xv/pJ0VgcdTksmWnXx5+YyT1GsnnGkHg84Z/r/C