Home Content News Malware Wave Forces Arch Linux To Suspend AUR Package Adoptions

Malware Wave Forces Arch Linux To Suspend AUR Package Adoptions

0
1
ArchLinux
ArchLinux

Arch Linux has suspended AUR package adoptions after attackers exploited its community maintenance model to inject malware, marking the third supply-chain security incident targeting the repository since June.

Arch Linux has temporarily disabled package adoptions on the Arch User Repository (AUR) after attackers exploited the adoption mechanism to inject malicious code through follow-up commits, prompting the project to act against an ongoing supply-chain attack.

Robin Candau, Arch Linux DevOps team member, confirmed the move, stating, “Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation.” He also urged the community to “stay vigilant” and report suspicious package adoption events or unresolved malicious commits.

The incident is the third security breach affecting the AUR since June 2026, pointing to a sustained campaign targeting the community repository. Attackers abused the feature that allows registered users to adopt orphaned packages, thereby gaining full commit access to their Git repositories.

According to AUR contributors, at least 27 packages have been compromised. The malicious packages contained ELF binaries disguised as tools named “linter”, “hasher” and “minifier”. Known affected packages include archutil, boringssl-git and icloudpd, although investigators note the list may grow.

The latest attack follows Sonatype’s “Atomic Arch” campaign in June, which compromised more than 1,500 orphaned packages using a malicious npm dependency, and another mid-June campaign that altered more than 70 packages with Russian-language spam.

The Australian Cyber Security Centre has also warned that software repositories are increasingly being targeted by supply-chain attackers, posing a significant and ongoing organisational security risk. Arch Linux is one of the world’s most influential open-source Linux distributions and forms the basis of projects including Valve’s SteamOS.

LEAVE A REPLY

Please enter your comment!
Please enter your name here