# Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

**URL:** https://discuss.privacyguides.net/t/arch-linuxs-aur-sees-more-than-400-packages-compromised-with-malware/38514
**Category:** News
**Tags:** article
**Created:** 2026-06-12T19:53:22Z
**Posts:** 3

## Post 1 by @seize — 2026-06-12T19:53:22Z

> **[Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware](https://www.phoronix.com/news/Arch-Linux-AUR-400-Compromised)**
>
> The Arch Linux User Repository 'AUR' was hit by a large-scale malware campaign this week with more than 400 of these user-supplied packages being compromised.

> Since yesterday Arch Linux maintainers have been working to reset/delete all of the malicious content and banning affected accounts. Over 400 packages are believed impacted by this latest malware campaign for Arch Linux’s AUR. Again, to be completely clear, this just is affecting AUR packages and not the official Arch Linux packages.

For the Arch Linux users here you may want to be extra cautious with AUR updates.

---

## Post 2 by @EsperZero — 2026-06-13T13:50:44Z

Advise to all Arch Users especially those using Arch based distros for the first time

some advisory until this resolves

1. Safest approach: Only update your packages exclusively in `pacman` as this will not interfere with AUR packages and the Arch Repository is more heavily vetted than the AUR
2. Risky but if you choose: If you do take the approach of updating the AUR, When the helper asks you to see the changes, Before `cleanbuild `MAKE SURE TO SEE NEW CHANGES, if there are new changes to pkgbuild that installs sketchy python or npm libraries or whatever library, IMMEDIATELY ABORT (Ctrl+Z or Ctrl+C) and DO NOT Update OR EXCLUDE COMPROMISED AUR packages

but hopefully it will be resolved soon so that AUR Packages don’t remain outdated in systems

---

## Post 3 by @TheManWithNoPlan — 2026-06-13T14:52:52Z

This was always going to happen.

I’ve used Gentoo on multiple machines when it was only single core 32 bit processors, BTW.
