Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

Since yesterday Arch Linux maintainers have been working to reset/delete all of the malicious content and banning affected accounts. Over 400 packages are believed impacted by this latest malware campaign for Arch Linux’s AUR. Again, to be completely clear, this just is affecting AUR packages and not the official Arch Linux packages.

For the Arch Linux users here you may want to be extra cautious with AUR updates.

Advise to all Arch Users especially those using Arch based distros for the first time

some advisory until this resolves

  1. Safest approach: Only update your packages exclusively in pacman as this will not interfere with AUR packages and the Arch Repository is more heavily vetted than the AUR
  2. Risky but if you choose: If you do take the approach of updating the AUR, When the helper asks you to see the changes, Before cleanbuild MAKE SURE TO SEE NEW CHANGES, if there are new changes to pkgbuild that installs sketchy python or npm libraries or whatever library, IMMEDIATELY ABORT (Ctrl+Z or Ctrl+C) and DO NOT Update OR EXCLUDE COMPROMISED AUR packages

but hopefully it will be resolved soon so that AUR Packages don’t remain outdated in systems

1 Like

This was always going to happen.

I’ve used Gentoo on multiple machines when it was only single core 32 bit processors, BTW.