Hundreds of AUR packages attacked by infostealer

Lobsters Hottest News

Summary

Hundreds of Arch User Repository (AUR) packages were compromised by an infostealer malware. Package maintainers are working to remove malicious commits and ban the involved accounts.

<p>More info in Mastodon post: <a href="https://gaysex.cloud/notes/andaxow7itfn05x9" rel="ugc">https://gaysex.cloud/notes/andaxow7itfn05x9</a></p> <p>List of affected packages: <a href="https://gr.ht/aur_pkg_list.txt" rel="ugc">https://gr.ht/aur_pkg_list.txt</a></p> <p><a href="https://lobste.rs/s/ta0sem/hundreds_aur_packages_attacked_by">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 06/11/26, 09:37 PM

# AUR REPORT THREAD - Aur-general Source: [https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/](https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/) ## [Jonathan Grotelüschen](https://lists.archlinux.org/archives/users/608d2b61a46f495fb24c5616ae0795d8/) 11 Jun 202611 Jun '26 5:47 p\.m\. Hi everyone, we’re working hard to reset/delete all malicious commits and ban the accounts\. If you find more malicious packages, please \*\*send them as a reply to this email\*\* to keep them all in one thread\. Thanks\! \-\- tippfehlr Attachments: - [OpenPGP\_signature\.asc](https://lists.archlinux.org/archives/list/[email protected]/message/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/attachment/3/OpenPGP_signature.asc)\(application/pgp\-signature — 228 bytes\) [0](https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/#like)[0](https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/#dislike) [Show replies by date](https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/?sort=date) ![Loading...](https://lists.archlinux.org/static/hyperkitty/img/ajax-loader.gif) 0 Age \(days ago\) 0 Last active \(days ago\) [List overview](https://lists.archlinux.org/archives/list/[email protected]/) [Download](https://lists.archlinux.org/archives/list/[email protected]/export/aur-general@lists.archlinux.org-FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4.mbox.gz?thread=FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4)36 comments 5 participants [Add to favorites](https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/#AddFav)[Remove from favorites](https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/#RmFav) ### tags ### participants \(5\) - André Herbst - Cristian Pereira - Iyán Méndez Veiga - Jonathan Grotelüschen - Rafał Lichwała

Similar Articles

AURpocalypse now: a look at the recent AUR attacks

Hacker News Top

The Arch User Repository (AUR) has been under sustained attack, with attackers creating new accounts to adopt orphaned packages and push malicious updates. The project has temporarily disabled new-user registration, but long-term security solutions remain unclear.

Malicious Packages Spreading in AUR

Lobsters Hottest

Security alert: malicious packages are being spread in the Arch User Repository (AUR), posing a risk to Arch Linux users.

Arch Linux disables AUR package adoption

Hacker News Top

Arch Linux has disabled adoption of orphaned AUR packages after a wave of malicious package adoptions pushed remote-access trojans to users, following earlier account-registration suspensions and a previous attack campaign.