• brokenwing@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    1 day ago

    What to do if I found a package I installed to be in that list? libgdata to be specific?

    Edit: Seems that the libgdata package was last installed on March 05.

    • Petersson@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      2 days ago

      Have a check if you updated it recently (PKGBUILD history, about June 10-12). If not you’re fine.

      If:

      • Rotate all credentials — browser passwords, SSH keys, API tokens, and cloud access keys
      • Scan for suspicious processes masquerading as kernel threads using tools like rkhunter or chkrootkit (E: It’s supposed to be an eBPF rootkit)

      (reference)

      Personally I would reset everything if I got anything, to kill both any infection and my paranoia. Then reset credentials.