Arch Linux AUR Pushes Suspended Amid Malicious Package Flood

Pushes to arch AUR are suspendended right now.

Arch Linux's AUR (Arch User Repository) has temporarily disabled package pushes and adoptions following a surge of malicious package adoptions and commits. The Arch Linux DevOps team, represented by Robin Candau (Antiz), announced the suspension on the aur-general mailing list, urging users to report suspicious activity. The team will provide updates once the situation is resolved.

We have now disabled pushes altogether as well for the moment, while we handle the situation.
  1. numeri

    Well, I guess I'll avoid updating for the next few days. A bit worrisome that I did so last night.

    I wish I had a clear operating system to switch to for safety and the benefits that come with the AUR or the Nix ecosystem. Unfortunately it seems that the era of being able to naively and gratefully trust in the armies of volunteer maintainers is over.

    LLMs make large scale and long-term attacks easy and cheap. You could (and if I was a three letter agency, I would probably do so!) maintain ten thousand packages as three thousand separate "individuals" for years before cashing in the trust you've built up.

  2. meribold

    The explicit expectation with the AUR has always been that you can't blindly trust the PKGBUILD files. It's more like running an installer from a random website on Windows than it is to using official distro repositories. I think the wiki also always advised against using AUR helper tools that blur the lines between official repositories and the AUR.

  3. DavideNL

    Also see: https://news.ycombinator.com/item?id=49123208

  4. evil-olive

    for context, 2 days ago:

    Arch Linux disables AUR package adoption (https://news.ycombinator.com/item?id=49123208)

  5. lenerdenator

    Sadly, this is the future of a lot of FLOSS development unless people start to see their projects as their legacy instead of a simple hobby or a way to scratch an itch.

    Once your project obtains any sort of real notoriety, it starts having a blast radius, and you need to have at least some idea of who is pushing what to it when and why. The Linux kernel has a pretty good system of this for the time being with Linus being BDFL. There's governance, there's a standard, and most importantly, there are resources coming in.

    If your wares are being used by large groups of people you've never met and in ways you cannot possibly imagine, then it's time to start doing the boring paperwork and political parts of managing the community around it, not just pushing commits and adding features.

More from this day

2026-08-02