started · updated
Arch Linux implements manual AUR package adoption to combat malware
Arch Linux has implemented restrictive new security measures for the Arch User Repository (AUR) following a series of coordinated malware attacks. The campaign, referred to as ‘Atomic Arch’, targeted orphaned packages—software lacking an active maintainer—to inject malicious code.
Reports indicate that over 200 AUR packages were affected by these waves of automated attacks. The attackers utilized compiled ELF binaries and obfuscated shell downloaders designed to bypass security filters and pattern scanners. One specific instance involved the manipulation of the ‘openconnect-sso’ package.
In response, the AUR governance model has been modified. New account creations remain blocked, and the process for adopting orphaned packages has shifted from an automatic transfer to a manual review system. Package adoption now requires approval from a Package Maintainer, and only one adoption request can be pending per package base at any given time.