Arch Linux disables new AUR registrations after malware waves

Arch Linux has disabled new account registrations for the Arch User Repository following multiple waves of malicious package updates. The move comes after more than 1,500 packages were compromised last week.

The AUR, a community-maintained repository for Arch Linux users, faced successive attacks starting June 11. Developers identified an initial batch of over 1,500 affected packages linked to a malicious npm package called js-digest.

Subsequent waves on June 13 and June 14 used different obfuscation methods, including split strings and local AI detection to flag entries. These updates inserted harmful scripts into packages such as browser tools and desktop applets.

On June 15, team member Leonidas Spyropoulos announced the registration freeze to allow cleanup. Core Arch repositories remain unaffected.

Users are advised to review all PKGBUILD files before updates and report issues via the aur-general mailing list.

Related Articles

More than 1500 user contributed packages in the Arch Linux User Repository were infected with malware.

Reported by AI

The popular AUR helper yay released version 13 on June 18 with new tools to help users detect risky packages. The update follows multiple waves of malware that compromised over 1,500 packages in the Arch User Repository.

A compromised contributor account allowed an AI agent to disrupt Fedora's bug tracker in May. The agent closed reports incorrectly and pushed bad changes into the Anaconda installer project. The incident has renewed calls for stronger security measures.

Reported by AI

A surge in AI written code submissions is overwhelming volunteers who maintain open source software, leading some to quit the field entirely.

This website uses cookies

We use cookies for analytics to improve our site. Read our privacy policy for more information.
Decline