We are currently experiencing a high volume of malicious package adoptions and updates in the Arch User Repository.

We are actively working to track down existing malicious commits and attempting to prevent additional malicious commits from being pushed. While this is happening, and while we work to create a more permanent solution, users may see issues with the following:

  • Creating new accounts on the AUR
  • Pushing package updates
  • Adopting or creating new packages

We continue to encourage all users of AUR packages to review all PKGBUILD and install script changes when updating, especially during this time. If you notice suspicious commits to a package that you use, please reach out to Arch staff via the aur-general mailing list with more information.

  • AssortedBiscuits [they/them]@hexbear.netOP
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 months ago

    It’s definitely exciting times. I don’t like how the AUR is toted by the Arch community as something that makes Arch stand out compared with other distros until something like this happens then it’s “Well, you should only use the AUR if you know what you’re doing. Arch is explicit about how the AUR hasn’t been vetted, so you can’t pin this on Arch. Caveat emptor.”

    • TheModerateTankie [any]@hexbear.net
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 months ago

      It’s wierd that it’s so heavily promoted to new users these days. “Just read all the notes before you update, bro” on a system that constantly updates…