logo

Ubuntu 'command-not-found' Tool Could Trick Users into Installing Rogue Packages

ID: ca7017ee-0748-5b65-9396-1ec14b6a2313

STIX ID: report--ca7017ee-0748-5b65-9396-1ec14b6a2313

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-02-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Aqua Security researchers disclosed that Ubuntu's default command-not-found utility can be manipulated via the snap ecosystem: attackers who claim snap names (including names matching APT packages) or register aliases/typosquatted snaps can have their malicious snaps suggested above legitimate APT packages, potentially leading users to install counterfeit software. The issue stems from command-not-found delegating snap suggestions to the advicesnap mechanism, and Aqua warns developers and users to register associated snap names and verify package sources to prevent impersonation and supply-chain abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.