{"id":581487,"date":"2026-08-03T09:06:08","date_gmt":"2026-08-03T09:06:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/581487\/"},"modified":"2026-08-03T09:06:08","modified_gmt":"2026-08-03T09:06:08","slug":"malware-wave-forces-arch-linux-to-suspend-aur-package-adoptions","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/581487\/","title":{"rendered":"Malware Wave Forces Arch Linux To Suspend AUR Package Adoptions"},"content":{"rendered":"<p>            <a href=\"https:\/\/www.opensourceforu.com\/wp-content\/uploads\/2026\/07\/ArchLinux-e1784618886915.png\" data-caption=\"ArchLinux\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" width=\"696\" height=\"444\" class=\"entry-thumb td-modal-image\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/08\/ArchLinux-696x444.png\"   alt=\"ArchLinux\" title=\"ArchLinux\"\/><\/a>ArchLinux<\/p>\n<p>Arch Linux has suspended AUR package adoptions after attackers exploited its community maintenance model to inject malware, marking the third supply-chain security incident targeting the repository since June.<\/p>\n<p>Arch Linux has temporarily disabled package adoptions on the Arch User Repository (AUR) after attackers exploited the adoption mechanism to inject malicious code through follow-up commits, prompting the project to act against an ongoing supply-chain attack.<\/p>\n<p>Robin Candau, Arch Linux DevOps team member, confirmed the move, stating, \u201cDue to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation.\u201d He also urged the community to \u201cstay vigilant\u201d and report suspicious package adoption events or unresolved malicious commits.<\/p>\n<p>The incident is the third security breach affecting the AUR since June 2026, pointing to a sustained campaign targeting the community repository. Attackers abused the feature that allows registered users to adopt orphaned packages, thereby gaining full commit access to their Git repositories.<\/p>\n<p>According to AUR contributors, at least 27 packages have been compromised. The malicious packages contained ELF binaries disguised as tools named \u201clinter\u201d, \u201chasher\u201d and \u201cminifier\u201d. Known affected packages include archutil, boringssl-git and icloudpd, although investigators note the list may grow.<\/p>\n<p>The latest attack follows Sonatype\u2019s \u201cAtomic Arch\u201d campaign in June, which compromised more than 1,500 orphaned packages using a malicious npm dependency, and another mid-June campaign that altered more than 70 packages with Russian-language spam.<\/p>\n<p>The Australian Cyber Security Centre has also warned that software repositories are increasingly being targeted by supply-chain attackers, posing a significant and ongoing organisational security risk. Arch Linux is one of the world\u2019s most influential open-source Linux distributions and forms the basis of projects including Valve\u2019s SteamOS.<\/p>\n","protected":false},"excerpt":{"rendered":"ArchLinux Arch Linux has suspended AUR package adoptions after attackers exploited its community maintenance model to inject malware,&hellip;\n","protected":false},"author":2,"featured_media":581488,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[61,60,80],"class_list":["post-581487","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ie","tag-ireland","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/581487","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=581487"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/581487\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/581488"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=581487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=581487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=581487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}