< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Arch Linux Suspends AUR Package Adoption After Malicious Supply‑Chain Attacks

The Arch Linux DevOps team temporarily disabled the package‑adoption feature of the Arch User Repository (AUR) after detecting a wave of malicious takeovers. Attackers exploited the AUR’s policy that allows community members to adopt orphaned packages, injecting harmful build scripts into more than 400 community‑maintained packages. The compromised updates could enable credential theft, remote code execution, or backdoor installation on systems that automatically install AUR packages.

The suspension was announced by Robin Candau (online as Antiz) in a mailing‑list post, stating that adoption is disabled while the scope of the compromise is investigated. Arch Linux is urging users to report suspicious adoption events and unreviewed commits to help contain the threat. No timeline has been set for restoring the adoption feature.

The incident highlights the supply‑chain risks inherent in decentralized software repositories and the need for stricter safeguards and community vigilance.

Entities

Arch Linux · Arch User Repository · Robin Candau