Skip to content
Tech News
← Back to articles

Arch Linux disables AUR package adoption

read original more articles
Why This Matters

The Arch Linux DevOps team has disabled AUR package adoption to combat a surge in malicious package uploads, including remote-access trojans that threaten user security. This move highlights the ongoing challenges in maintaining software supply chain security and protecting users from malware. It underscores the importance of vigilant package management and security measures in open-source ecosystems.

Key Takeaways

The Arch Linux DevOps team has announced that adoption of orphaned packages in the Arch User Repository (AUR) has been disabled due to " the current influx of malicious package adoptions and follow-up commits made via the AUR ". Michael Taggart has posted a brief analysis of the malware being added to a long list of packages in this round of attacks. The payload appears to be an remote-access trojan (RAT) that takes commands over the Tor network and attempts to upload a wide range of user data.

The project had suspended new account registration in June. That followed a campaign in which an attacker or attackers created new accounts to adopt orphaned packages and push malicious updates to them that would install malware on user systems. AUR registration was reopened on July 13 after the DevOps team added some minor, and apparently ineffective, restrictions on creating new accounts.

to post comments