Ссылка
click to show
click to show
Arch Linux AUR Compromised - 400+ Packages Infected with Malware
Summary
The Arch Linux User Repository "AUR" was hit by a large-scale malware campaign this week with more than 400 of these user-supplied packages being compromised. To be completely clear, this just is affecting AUR packages and not the official Arch Linux packages. The attack is also seemingly ongoing, with more packages being discovered by the hour.
EDIT: It seems that a partially complete list of compromised packages can be found here:
https://md.archlinux.org/s/SxbqukK6IA
It appears that a CachyOS maintainer has made a very basic checker script (in addition to our attempts elsewhere in this thread) to give your system a cursory check for affected packages.
This github is also linked in the thread, which has done their best to combine community efforts and provide tooling to check your system. As always please read through and make sure you understand any scripts you're running on your system. At the time I'm making this edit, I don't see anything concerning, but as they aren't my work I can't vouch for them and they are at your own risk.
Quotes
Quote
2026-06-12 - Campbell Jones
We are currently experiencing a high volume of malicious package adoptions and updates in the Arch User Repository.
We are actively working to track down existing malicious commits and attempting to prevent additional malicious commits from being pushed. While this is happening, and while we work to create a more permanent solution, users may see issues with the following:
Creating new accounts on the AUR
Pushing package updates
Adopting or creating new packages
We continue to encourage all users of AUR packages to review all PKGBUILD and install script changes when updating, especially during this time. If you notice suspicious commits to a package that you use, please reach out to Arch staff via the aur-general mailing list with more information.
My thoughts
This should be a cautionary tale for newer users, especially on more user-friendly distros like CachyOS which make it easier to access the (extremely useful) AUR. The AUR is not officially supported, it is extremely inconvenient, but you should be reading through the PKGBUILD for every AUR installation you use. If you don't have the knowledge of how to do so, consider alternative sources for your program, or alternative software options.
Sources
Newsletter: https://archlinux.org/news/active-aur-malicious-packages-incident/
Arch Forum: https://lists.archlinux.org/archives/list/[email protected]/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/
CachyOS Forum: https://discuss.cachyos.org/t/aur-compromised-1500-packages-affecte