AUR compromise
2026-06-12 15:32:31.702021+02 by Dan Lyke 0 comments
The Arch Linux AUR (Arch User Repository) had over 400 packages compromised with malware
There's a thread on the public AUR Mailing List with people reporting packages, where it seems like over 400 packages were hit with the issue. Arch packager Jonathan Grotelüschen mentioned work was ongoing to "reset/delete all malicious commits and ban the accounts".
ifin: 400+ AUR Packages Compromised with Infostealer and Rootkit points to Taggart :ifin: @mttaggart@infosec.exchange
I'm trying to understand the details of AUR processes for submitting PKGBUILDs. In other words, how exactly did this happen? arojas submitted hundreds of changes to PKGBUILD or related files. And they were just...accepted? What am I missing?
Edit: What I missed was this was pure impersonation. The maintainer is fine, but the process was vulnerable to spoofing.