You are not logged in.
Pages: 1
Seems more attacks to the extended infrastructure recently, but I couldn't find any statement about this.
Kernel is now only installed on less than half of systems haha.
https://pkgstats.archlinux.de/packages
Meanwhile the tools necessary to poison the statistics are the only packages above 44% install rate:
curl
100%
gzip
99.99%
pkgstats
99.97%
python
99.95%
discord
67.38%
dash
59.56%
equibop-bin
55.7%
Discord... yeah.
No coincidence with all the other recent attacks.
Anyone have any insight?
Last edited by tekstryder (2026-01-05 18:20:59)
Offline
I have created a thread on forum.archlinux.de in case when our admin (also for pkgstats) don't recognize this thread.
https://forum.archlinux.de/d/35695-pkgs … os-auf-org
My avatar: "It's not just a toilet... a FERGUSON. The King of bowls. Sit down and give me your best shot." Al Bundy
Offline
I am looking into this. Unfortunately it looks like someone posted millions of invalid package data to screw up the data for December. I am trying to analyse this and hope those invalid data can be removed (mostly).
Offline
seems the person that did this uses discord.. hmm. id expect no less.
Offline
I have created a thread on forum.archlinux.de
I am trying to analyse this and hope those invalid data can be removed (mostly).
Thank you both for the quick responses.
Hopefully the attacker left a recognizable fingerprint pattern in the false submissions to make removal of the bad data fairly straightforward.
Offline
Stats are looking back to normal. Nice!
Marking as SOLVED.
Offline
This seems to have happened again for January. To my eye the fake data looks much more difficult to tease apart than last time.
Offline
Can you be more specific about what data looks skewed to you?
Offline
Pages: 1