AUR-scanner
Scanner to check if Arch Linux AUR packages have been compromised
Library Rated 7 Oct 2026
- Built by
Tetstack
Bloat
168/500Where it landed on the scale
0
300
400
Summary
This is a quick, honest response tool to a real AUR security incident. It works in a thin way, the creator says it misses a lot, and the repo now points to a successor project (SAUR). There's no pricing, payments, docs or support channel, and it's mostly a one-off utility.
Bloat · Not much here works or looks likely to last, yet.
Breakdown
Five measures, 100 points each. Open the receipts under any of them to see the posts and pages behind the points.
Viability
Is there a real problem, someone who would pay, and a market this builder can actually reach?
The problem was real for Arch users during the attack, but the tool is free, GPL-licensed and incident-specific, with no path to anyone paying. The README now just points to a successor, so it's been superseded.
22/100
Rubric 21–40A real problem, but no plausible path to anyone paying, or a market well out of this builder's reach.
Receipts (3)
Built to let Arch users check whether they installed the compromised npm packages or affected PKGBUILDs.
“So for my my fellow Arch linux users, as some AUR pkg have been compromised. https://github.com/PicasoTheDeal/AUR-scanner Here is my github repo for you to check if you have installed any of the npm atomic pkg or not and if the PKGBUILD have been affected”
Post · @Tetstack · 15 Jun 2026 · open on Telegram (opens in a new tab)
The repo text says it's succeeded by SAUR, so this one is effectively retired.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/AUR-scanner (opens in a new tab)
GPL-3.0 licensed with no releases and no pricing, so there's no model for charging.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/AUR-scanner (opens in a new tab)
Moat
What stops someone copying it?
A small script that checks for known indicators is easy to rebuild, and the creator says it misses a lot. Nothing here compounds, like data or a distribution channel.
8/100
Rubric 0–20A thin wrapper or a clone that anyone here could rebuild in a weekend.
Receipts (2)
The creator admits it misses a lot and was written quickly without deep Python knowledge.
“I don't vibe code most of the time but there are projects like the AUR-scanner which I build at that time, I don't really know python that much but you know had to make a tool for the attack back then. it misses a lot of stuff but was better then doing nothing”
Post · @Tetstack · 2 Sept 2026 · open on Telegram (opens in a new tab)
No releases, no owned distribution, and it's already succeeded by another repo.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/AUR-scanner (opens in a new tab)
Momentum
Did the updates keep coming?
Commits landed in June, July and August, with most activity in the first week after the attack and a few later bursts. It then moved to a successor repo, so the pace has tapered.
67/100
- Sustained shipping27/60
Worked on across 3 months.
- Consistency40/40
Updates in 3 of 3 months.
Receipts (2)
Earliest post about it.
“So for my my fellow Arch linux users, as some AUR pkg have been compromised. https://github.com/PicasoTheDeal/AUR-scanner Here is my github repo for you to check if you have installed any of the npm atomic pkg or not and if the PKGBUILD have been affected”
Post · @Tetstack · 15 Jun 2026 · open on Telegram (opens in a new tab)
Most recent post about it.
“I don't vibe code most of the time but there are projects like the AUR-scanner which I build at that time, I don't really know python that much but you know had to make a tool for the attack back then. it misses a lot of stuff but was better then doing nothing”
Post · @Tetstack · 2 Sept 2026 · open on Telegram (opens in a new tab)
Infrastructure
Does a real, working product exist?
A working but thin Python scanner exists on GitHub. The creator says it misses a lot, and it has no releases, packaging or docs beyond the repo.
67/100
- It's live20/20
https://github.com/PicasoTheDeal/AUR-scanner responded when checked.
- HTTPS5/5
Hosted on a platform (store, GitHub or Telegram), so HTTPS is the platform's.
- Real product25/35
A working scanner exists on GitHub with several days of commits, but the creator calls it incomplete and it ships no releases or packaging.
- Own home0/10
No home found.
- Maintained15/15
Last sign of shipping 2026-09-02.
- Operations2/15
It's a single repo on one platform with no docs site, API, accounts or status page beyond the repo itself.
Receipts (4)
https://github.com/PicasoTheDeal/AUR-scanner responded when checked.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/AUR-scanner (opens in a new tab)
Creator says the tool works but misses a lot of stuff.
“I don't vibe code most of the time but there are projects like the AUR-scanner which I build at that time, I don't really know python that much but you know had to make a tool for the attack back then. it misses a lot of stuff but was better then doing nothing”
Post · @Tetstack · 2 Sept 2026 · open on Telegram (opens in a new tab)
Commits across June to August, but zero releases.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/AUR-scanner (opens in a new tab)
Only a GitHub repository, with a pointer to a successor repo.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/AUR-scanner (opens in a new tab)
Sustainability
Is it being set up to last?
There's no distribution beyond the repo, no payments, no pricing, no legal pages, and no support channel. It was a free response to one incident and the work has since moved to a successor.
4/100
- Distribution0/30
No working way to get it was found.
- Payments0/15
No payment provider found.
- Pricing0/10
No pricing found on the site.
- Revenue0/5
Nothing in the posts or repo shows paying customers or revenue.
- Privacy policy0/7
No privacy policy found.
- Terms0/5
No terms of service found.
- Support0/8
No support contact found.
- Commitment4/20
The creator kept committing for a couple of months and started a successor project, but there's no team, roadmap or dedicated community.
Receipts (3)
The post offers the tool for free to fellow Arch users.
“So for my my fellow Arch linux users, as some AUR pkg have been compromised. https://github.com/PicasoTheDeal/AUR-scanner Here is my github repo for you to check if you have installed any of the npm atomic pkg or not and if the PKGBUILD have been affected”
Post · @Tetstack · 15 Jun 2026 · open on Telegram (opens in a new tab)
Commit days run from 2026-06-15 to 2026-08-07, and the homepage field links to SAUR.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/AUR-scanner (opens in a new tab)
Creator describes it as a stopgap made at the time of the attack.
“I don't vibe code most of the time but there are projects like the AUR-scanner which I build at that time, I don't really know python that much but you know had to make a tool for the attack back then. it misses a lot of stuff but was better then doing nothing”
Post · @Tetstack · 2 Sept 2026 · open on Telegram (opens in a new tab)