# Arch Linux AUR supply-chain attacks

> Live situation record from CLSTR: https://clstr.news/situations/arch-linux-aur-supply-chain-attacks
> Updated: 2026-08-10T01:34:50.000Z. Sources: 2. Developments: 2.

The Arch Linux DevOps team temporarily suspended the package-adoption feature of the Arch User Repository (AUR) following a wave of malicious supply-chain attacks. Attackers exploited policies allowing community members to adopt orphaned packages, injecting harmful build scripts into over 400 community-maintained packages to facilitate credential theft, remote code execution, or backdoor installations.

Following the investigation into these coordinated attacks, which have been referred to as ‘Atomic Arch’, the AUR governance model was modified. The campaign targeted orphaned packages using compiled ELF binaries and obfuscated shell downloaders to bypass security filters. In response, Arch Linux transitioned from an automatic transfer system to a manual review process. Package adoption now requires approval from a Package Maintainer, and only one adoption request can be pending per package base at any given time. Additionally, new account creations remain blocked.

## Timeline

### 2026-08-10: Arch Linux implements manual AUR package adoption to combat malware

Arch Linux has introduced manual review requirements for AUR package adoption following the ‘Atomic Arch’ malware campaign, which targeted over 200 orphaned packages with malicious code.

2 sources. https://clstr.news/cluster/arch-linux-implements-manual-aur-package-adoption-to-combat-malware

### 2026-08-01: Arch Linux Suspends AUR Package Adoption After Malicious Supply‑Chain Attacks

Arch Linux has halted AUR package adoption after attackers compromised over 400 community packages, injecting malicious code. The move, announced by Robin Candau, aims to stop further spread while the issue is

3 sources. https://clstr.news/cluster/arch-linux-suspends-aur-package-adoption-after-malicious-supplychain-attacks

---
Cite as: Arch Linux AUR supply-chain attacks. CLSTR, https://clstr.news/situations/arch-linux-aur-supply-chain-attacks
