news
Arch’s AUR Besieged
-
LWN ☛ Arch GNU/Linux disables AUR package adoption
The Arch GNU/Linux DevOps team has announced that adoption of orphaned packages in the Arch User Repository (AUR) has been disabled due to "
the current influx of malicious package adoptions and follow-up commits made via the AUR
". -
Unicorn Media ☛ New Attack Puts Arch’s AUR Into Lockdown… Again
Arch Linux’s AUR faces a fresh security scare, prompting another round of lockdown measures from the project’s DevOps team.
-
XDA ☛ Arch Linux's AUR is under attack as malicious packages begin flooding the repository
It's a common misconception that Linux is still totally free of malware; in truth, we often see intricate and coordinated attacks on the open-source ecosystem. For instance, Arch Linux's repository, AUR, has seen a wave of new malicious commits enter the system, prompting DevOps maintainers to temporarily disable package adoptions while they clean up the attack.
Resignation:
-
Resignation - Arch-dev-public - lists.archlinux.org
It's been almost a decade since I met Jelle, Chris, Levente and Remi at 33C3 to be (peacefully) coerced into joining the security team, and almost 9 years since I became a package maintainer.
It's time to let go.
-
Resigning from Arch Linux
Things are changing and it’s a good time to let go.
I still intend to continue working on my projects around TPMs, secure boot and platform security stuff.
Microsoft-connected site:
-
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
The decision was announced on the distribution's mailing list by contributor Robin Candau, who said that the situation is temporary until a solution is found.
“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.
Late coverage:
-
Arch Linux Freezes AUR Adoption: Tor-Backed Rust Infostealer Bypasses June Defenses in Third Wave
The attackers behind the Atomic Arch supply chain campaign have adapted. After Arch Linux developers purged more than 1,900 compromised packages and declared the community repository clean in mid-June, the threat returned with a delivery mechanism specifically engineered to evade the detection signatures that caught the earlier waves — and this time the project's response was not a cleanup, but a lockdown.
Robin Candau, a contributor acting on behalf of the Arch Linux DevOps team, posted an emergency notice to the project's official mailing list on July 30, 2026. "Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation," Candau wrote. "We will send a follow-up once we're able to. In the meantime, feel free to report suspicious adoption events or commits that haven't been dealt with yet, and stay vigilant!" No timeline for restoring the adoption mechanism has been given.
GoL:
-
Arch Linux AUR hit with another wave of malware | GamingOnLinux
After previously dealing with a big wave of malware in the Arch Linux AUR (Arch User Repository), another wave happened while I was off touching grass (short holiday).
Late coverage:
-
Onslaught of malware hits Arch Linux's major AUR repository, all uploads suspended
Arch, a major Linux distribution valued for giving users complete control and access to bleeding-edge software, has been forced to shut down all uploads to its AUR repository – the main way users install third-party software. Dozens of malicious packages have been flagged.