{"id":18252,"date":"2026-08-01T10:29:06","date_gmt":"2026-08-01T17:29:06","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=18252"},"modified":"2026-08-01T10:29:06","modified_gmt":"2026-08-01T17:29:06","slug":"arch-linux-aur-under-another-wave-of-malicious-packages-package-adoptions-halted","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/08\/01\/arch-linux-aur-under-another-wave-of-malicious-packages-package-adoptions-halted\/","title":{"rendered":"Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Halted"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I think these are primarily people adding new packages, but best to continue due diligence and check the PKGBUILD files diffs for packages you use from the AUR. And for some things you can just get the AppImage from the developer. I like to evaluate who the maintainer is and look through the comments, and for new software packages I haven&#8217;t used I&#8217;ll look through the whole PKGBUILD file.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.phoronix.com\/news\/Arch-Linux-AUR-Adoptions-Halted\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.phoronix.com\/news\/Arch-Linux-AUR-Adoptions-Halted<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_0dc49fa3-f5dc-4e2f-ae73-81f61d66fde8\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<p class=\"wp-block-paragraph\">By Michael Larabel<\/p>\n\n\n\n<figure class=\"wp-block-image alignright is-resized\"><img decoding=\"async\" src=\"https:\/\/www.phoronix.com\/assets\/categories\/archlinux.webp\" alt=\"ARCH LINUX\" style=\"width:180px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Last month the Arch Linux User Repository &#8220;AUR&#8221; saw <a href=\"https:\/\/www.phoronix.com\/news\/Arch-Linux-AUR-More-Than-1500\">more than 1,500 malicious packages<\/a> amid <a href=\"https:\/\/www.phoronix.com\/news\/Arch-Linux-AUR-More-Malware\">a sophisticated malware attack<\/a> and then also seeing an influx of <a href=\"https:\/\/www.phoronix.com\/news\/Arch-Linux-AUR-Russian-Spam\">spam and profanities<\/a> amid this community\/user-maintained repository for the popular Arch Linux distribution. Unfortunately, there is another round of AUR troubles.<br><br>The Arch Linux team <a href=\"https:\/\/lists.archlinux.org\/archives\/list\/aur-general@lists.archlinux.org\/message\/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP\/\">announced<\/a> that due to the current influx of malicious package adoptions, they have decided for now to disable package adoptions in AUR while they handle the situation. They encourage users as well to report suspicious adoption events\/comments and to stay vigilant.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><a href=\"https:\/\/www.phoronix.com\/image-viewer.php?id=2026&amp;image=arch_linux_lrg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/www.phoronix.net\/image.php?id=2026&amp;image=arch_linux_med\" alt=\"Arch Linux with GNOME desktop\"\/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">There is <a href=\"https:\/\/lists.archlinux.org\/archives\/list\/aur-general@lists.archlinux.org\/thread\/P4WIRHTFNH2YZWQHGBAKQWX5YOAFIDLY\/\">this mailing list thread<\/a> outlining AUR malware from yesterday and today. There are dozens of AUR packages this round from i915-sriov-dkms to rtk-git, boringssl-git\/hasher, archutil\/linter, warp-terminal-git, weather-display, astro-box, and many others.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I think these are primarily people adding new packages, but best to continue due diligence and check the PKGBUILD files diffs for packages you use from the AUR. And for some things you can just get the AppImage from the developer. I like to evaluate who the maintainer is and look through the comments, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-18252","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18252","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=18252"}],"version-history":[{"count":1,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18252\/revisions"}],"predecessor-version":[{"id":18253,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18252\/revisions\/18253"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=18252"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=18252"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=18252"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}