415.tech
AI & tech, from the frontlines of Silicon Valley
Arch Linux AUR malware hit at least 1,579 packages — and the list is still incomplete

Arch Linux AUR malware hit at least 1,579 packages — and the list is still incomplete

A supply-chain attack exploited the AUR's missing automated security review to compromise at least 1,579 community-maintained packages; maintainers deleted all identified malicious commits but acknowledged the 1,579-package tally does not cover every affected repository. Any Arch system that pulled AUR packages during the window is in an unknown state until manually audited — no automated rollback or affected-user notification exists, and the infection vector, payload, and full user count were still undisclosed at time of reporting.

Source: phoronix.com

Post on XEmail

it's a "list containing many (but not all) of the affected packages"

Arch Linux developers

Why this matters

  • → 1,579+ Arch packages compromised; users can't identify infections without manual audit.
  • → AUR lacks automated security scanning, enabling supply-chain attacks at scale.
  • → No rollback mechanism or affected-user notification system exists.
Supply chain catastrophe