Arch Linux disables AUR pushes amid malware influx
Following an influx of malicious package adoptions and subsequent commits, the Arch Linux DevOps team has temporarily disabled both package adoptions and pushes to the Arch User Repository (AUR) while they investigate and handle the situation. Users are encouraged to remain vigilant and report any suspicious adoptions or commits that have not yet been addressed.
This is a significant security incident for the Arch Linux community, as the AUR is a widely used source for user-contributed packages.
* The freeze on pushes and adoptions is a necessary and responsible measure to contain the threat and prevent further malicious packages from being distributed.
* This highlights the ongoing vulnerability of community-maintained package repositories to supply chain attacks.
* The incident underscores the importance of community auditing and the "use at your own risk" nature of the AUR, reminding users to always inspect PKGBUILDs before installing.
DISCOVERED
2h ago
2026-08-02
PUBLISHED
5h ago
2026-08-02
RELEVANCE
AUTHOR
EbNar