Malicious Packages Spreading in AUR

Lobsters Hottest News

Summary

Security alert: malicious packages are being spread in the Arch User Repository (AUR), posing a risk to Arch Linux users.

<p><a href="https://lobste.rs/s/b5k2ao/malicious_packages_spreading_aur">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 06/11/26, 09:37 PM

# Aur-general - lists.archlinux.org Source: [https://lists.archlinux.org/archives/list/[email protected]/](https://lists.archlinux.org/archives/list/[email protected]/) ## Activity Summary Post volume over the past**30**days\. ![Loading...](https://lists.archlinux.org/static/hyperkitty/img/ajax-loader.gif) The following statistics are fromInthe past**30**days: 80 participants31 discussions ## Most active posters ![Loading...](https://lists.archlinux.org/static/hyperkitty/img/ajax-loader.gif)

Similar Articles

Hundreds of AUR packages attacked by infostealer

Lobsters Hottest

Hundreds of Arch User Repository (AUR) packages were compromised by an infostealer malware. Package maintainers are working to remove malicious commits and ban the involved accounts.

AURpocalypse now: a look at the recent AUR attacks

Hacker News Top

The Arch User Repository (AUR) has been under sustained attack, with attackers creating new accounts to adopt orphaned packages and push malicious updates. The project has temporarily disabled new-user registration, but long-term security solutions remain unclear.

Arch Linux disables AUR package adoption

Hacker News Top

Arch Linux has disabled adoption of orphaned AUR packages after a wave of malicious package adoptions pushed remote-access trojans to users, following earlier account-registration suspensions and a previous attack campaign.