Arch Linux disables AUR package adoption

Hacker News Top News

Summary

Arch Linux has disabled adoption of orphaned AUR packages after a wave of malicious package adoptions pushed remote-access trojans to users, following earlier account-registration suspensions and a previous attack campaign.

No content available
Original Article
View Cached Full Text

Cached at: 07/31/26, 04:59 PM

# Arch Linux disables AUR package adoption Source: [https://lwn.net/Articles/1086489/](https://lwn.net/Articles/1086489/) The Arch Linux DevOps team has[announced](https://lists.archlinux.org/archives/list/[email protected]/message/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/)that adoption of orphaned packages in the Arch User Repository \(AUR\) has been disabled due to "the current influx of malicious package adoptions and follow\-up commits made via the AUR"\. Michael Taggart has posted[a brief analysis](https://discourse.ifin.network/t/new-aur-attack-prompts-adoption-lock/698?)of the malware being added to a[long list of packages](https://lists.archlinux.org/archives/list/[email protected]/thread/P4WIRHTFNH2YZWQHGBAKQWX5YOAFIDLY/)in this round of attacks\. The payload[appears to be](https://gist.github.com/ysf/57850cdee152da066ac51c07a452e883)an remote\-access trojan \(RAT\) that takes commands over the Tor network and attempts to upload a wide range of user data\. The project had[suspended new account registration](https://lists.archlinux.org/archives/list/[email protected]/message/4JRS73YVTE7JUYHHE3ZDUIHXYHXZ3YQQ/)in June\. That followed[a campaign](https://lwn.net/Articles/1077619/)in which an attacker or attackers created new accounts to adopt orphaned packages and push malicious updates to them that would install malware on user systems\. AUR registration was[reopened](https://lists.archlinux.org/archives/list/[email protected]/message/TT3OCFFNM6SBMUBKIVTHTKA6UZJNMXIJ/)on July 13 after the DevOps team added some minor, and apparently ineffective, restrictions on creating new accounts\. ---

Similar Articles

AURpocalypse now: a look at the recent AUR attacks

Hacker News Top

The Arch User Repository (AUR) has been under sustained attack, with attackers creating new accounts to adopt orphaned packages and push malicious updates. The project has temporarily disabled new-user registration, but long-term security solutions remain unclear.

Hundreds of AUR packages attacked by infostealer

Lobsters Hottest

Hundreds of Arch User Repository (AUR) packages were compromised by an infostealer malware. Package maintainers are working to remove malicious commits and ban the involved accounts.

Malicious Packages Spreading in AUR

Lobsters Hottest

Security alert: malicious packages are being spread in the Arch User Repository (AUR), posing a risk to Arch Linux users.