The Arch Linux DevOps team has disabled the adoption of orphaned packages and pushes in the Arch User Repository (AUR). This decision was made in response to a recent influx of malicious package adoptions and subsequent commits.
Robin Candau, a contributor, announced the temporary measure on the distribution's mailing list, stating that the situation is being handled and a follow-up will be provided once a solution is found.
The malicious activity involves attackers using remote-access trojans (RATs) and two-stage infostealers. These payloads take commands over the Tor network and attempt to upload user data, with the potential to spread laterally across systems.
A technical analysis by the Independent Federated Intelligence Network (IFIN) reported that the current campaign began on July 29 with the package 'openconnect-sso'. IFIN noted similarities to a previous campaign in June, including the use of the Tor network for staging.
This is not the first time the AUR has faced such attacks. In June, new account registrations were suspended after an attacker or attackers created accounts to adopt orphaned packages and push malicious updates. These updates installed malware, including a Linux rootkit and info-stealer, on user systems.
AUR registration was reopened on July 13 after minor restrictions were added to new account creation, which proved ineffective against the latest wave of attacks.
The temporary disablement aims to mitigate the spread of malware and protect users. Users are encouraged to report suspicious adoption events or commits that have not yet been addressed and to remain vigilant.
The Arch Linux DevOps team is working to resolve the situation and restore normal AUR functionality.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Arch Linux User Repository (AUR) has temporarily disabled package adoption and pushes due to an influx of malicious package adoptions and commits. This action was taken by the Arch Linux DevOps team to address security concerns and prevent further compromise of the repository.
Arch Linux has temporarily disabled package adoption in its Arch User Repository (AUR) following a rise in malicious package takeovers and commits. This action was taken after a new malware campaign, similar to a previous one in June, began distributing a two-stage infostealer through compromised or adopted AUR packages. The temporary disablement aims to mitigate the spread of malware that targets sensitive user data and can spread laterally across systems.
Arch Linux has disabled the adoption of orphaned packages in its Arch User Repository (AUR) following an influx of malicious package adoptions and commits. Attackers are using remote-access trojans (RATs) to upload user data, prompting this security measure.