yay v13 adds Lua hooks after AUR malware attacks

The popular AUR helper yay released version 13 on June 18 with new tools to help users detect risky packages. The update follows multiple waves of malware that compromised over 1,500 packages in the Arch User Repository.

yay now displays a timestamp showing how recently each package's PKGBUILD was last changed. This appears in search results, the yogurt prompt, and the upgrade menu.

Maintainer Jo Guerreiro said the timestamp serves only as an extra signal and does not indicate whether a package is safe or unsafe.

The release also introduces Lua-based hooks and configuration. Users can place a file at $XDG_CONFIG_HOME/yay/init.lua to script behaviors such as UpgradeSelect, AURPreInstall, and AURPostDownload.

These hooks allow automated checks before packages are installed. The update includes other fixes such as restored locale files and improved logging.

Related Articles

Arch Linux has disabled new account registrations for the Arch User Repository following multiple waves of malicious package updates. The move comes after more than 1,500 packages were compromised last week.

Reported by AI

More than 1500 user contributed packages in the Arch Linux User Repository were infected with malware.

This website uses cookies

We use cookies for analytics to improve our site. Read our privacy policy for more information.
Decline