Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
Summary
Arch Linux developers have contained a malware incident in the AUR user-contributed repository, deleting malicious commits affecting over 1,500 packages.
View Cached Full Text
Cached at: 06/13/26, 02:38 PM
Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages
Source: https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500

The day started out withArch Linux’s AUR user-contributed repository seeing more than 400 packages compromisedwith malware. Now in ending out the day they believe all affected commits have been addressed. But it ended up being more than 1,500 affected packages.
It was bad enough when finding out more than 400 AUR packages for Arch Linux users had been infected with malware but now that number has risen to around 900 a few hours ago and now in the end at more than 1,500 user-contributed packages.
In anupdatea few hours ago, it was believed around 900 packages were infected by malware in this week’s incident.
Then as of writing now, the last message in the thread over this security incident isnotingthat Arch Linux developers have deleted all the malicious commits they are aware of. Cited wasthis listthat puts the number of malware-affected packages at 1,579! Tons of software in this user-maintained Arch Linux user repository were impacted by this nasty security incident.
Even at 1,579 packages listed, that final updated noted, it’s a “list containing many (but not all) of the affected packages”. Ouch.
Similar Articles
Can I make realistic agents without paying for API keys?
Explores methods to build realistic AI agents without relying on paid API keys, likely using open-source models or free tiers.
JumpServer: Open-Source Privileged Access Management
JumpServer is an open-source Privileged Access Management (PAM) platform that provides secure, on-demand access to SSH, RDP, Kubernetes, Database, and RemoteApp endpoints through a web browser.
.garden TLD's change to a bad neighborhood
The .garden top-level domain is being flagged as a problematic zone, likely due to spam or abuse issues, making it a 'bad neighborhood' in the internet ecosystem.
Google warns EU's plans to weaken its monopoly could expose user data
Google warns that proposed EU regulations requiring it to share search data and open Android to competing AI assistants could lead to increased fraud and privacy risks, citing ease of de-anonymization with AI.
Qwen3-tts.cpp + Compose Desktop GUI
The developer improved qwen3-tts.cpp to run 5x realtime on RTX 5080 and created a cross-platform desktop GUI with Kotlin Compose Multiplatform, featuring voice cloning, streaming, and speaker embedding management.