Arch Linux locks down AUR signups amid wave of malicious commits
2 hours ago
4 languages5 countries7 sources
Attackers compromised over 400 packages in the Arch User Repository (AUR), injecting malicious code into build scripts to deploy an infostealer and rootkit. The malware targets browser cookies, SSH keys, GitHub credentials, and other sensitive data. Arch Linux maintainers are deleting the malicious content and banning involved accounts. Only user-contributed AUR packages are affected, not official Arch Linux packages.
How outlets framed it
All sources report a malicious attack on the Arch User Repository (AUR), but they differ in the scope and focus. Chinese and US outlets emphasize the number of compromised packages (over 400) and the technical details of the malware (infostealer, rootkit), while German and Russian reports mention larger numbers (1,600 or 1,577 packages) and highlight that the attack targeted only unofficial user packages, not the official Arch Linux repository. The tone is uniformly factual and warning, with no significant spin beyond the numerical discrepancy.
Also covering:
The Register
Arch Linux locks down AUR signups amid wave of malicious commits
BleepingComputer
Over 400 Arch Linux packages compromised to push rootkit, infostealer
IT之家
Arch Linux 项目用户软件仓库 AUR 遭恶意攻击,400+ 项目被投毒
ComputerBase
Arch Linux unter Feuer: Über 1.600 Pakete im AUR kompromittiert (Update)
Solidot
Arch Linux 逾四百 AUR 包被植入恶意程序
Heise Online
Angriffswelle auf Arch Linux: Hunderte Paketbeschreibungen mit Malware im AUR
OpenNET
Атакующие скомпрометировали 1577 пакетов в репозитории AUR