VDB
GCVE-110-AUR-2026-001183
GCVE-110-AUR-2026-001183
Advisory Published
The Arch User Repository (AUR) package `obfs4proxy-bin` was identified as malicious during the June 2026 AUR supply-chain compromise, in which an attacker pushed backdoored PKGBUILDs to roughly 1,900 packages. Building or installing the affected package executed attacker-controlled code. The malicious revision has since been removed from the AUR. Upstream package description: "The obfourscator - A Pluggable Transport Proxy Written in Go (This package is built by myself for thoes who live in countries with tor censored that cannot download the source in obfs4proxy package".
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| aur | obfs4proxy-bin | * (affected) | — |
Browse GCVE Records
74,147 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.