News: 0001640039

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

([Arch Linux] 5 Hours Ago AUR)


The Arch Linux User Repository "AUR" was hit by a large-scale malware campaign this week with more than 400 of these user-supplied packages being compromised.

Since yesterday Arch Linux maintainers have been working to reset/delete all of the malicious content and banning affected accounts. Over 400 packages are believed impacted by this latest malware campaign for Arch Linux's AUR. Again, to be completely clear, this just is affecting AUR packages and not the official Arch Linux packages.

[1]This Arch Linux mailing list thread goes over some of the affected AUR packages and the impact. There is also more information and discussion on this significant AUR event via the [2]CachyOS Forums .



[1] https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

[2] https://discuss.cachyos.org/t/aur-compromised-400-packages-affected-20260611/31040/19



When the lodge meeting broke up, Meyer confided to a friend.
"Abe, I'm in a terrible pickle! I'm strapped for cash and I haven't
the slightest idea where I'm going to get it from!"
"I'm glad to hear that," answered Abe. "I was afraid you
might have some idea that you could borrow from me!"