Techtimes Arch Linux Freezes AUR Adoption Amid Malware Surge
Article Content
- •Arch Linux has frozen AUR package adoption due to a surge in malicious takeovers.
- •The latest malware campaign began on July 29, 2026, affecting over 200 packages.
- •Attackers are using a two-stage infection method involving a Rust-based infostealer.
Arch Linux has temporarily disabled package adoption in the Arch User Repository (AUR) following a surge in malicious package takeovers. The decision was announced by contributor Robin Candau on July 30, 2026. Attackers exploited the orphaned package adoption system to push malicious updates, with estimates suggesting over 200 packages may be affected. The latest wave of attacks, which began on July 29, utilizes a two-stage infection method involving a Rust-based infostealer. This malware targets sensitive data, including browser credentials and SSH keys, and can execute commands remotely over Tor. The previous campaign in June had already compromised over 400 packages, distributing a Linux rootkit and info-stealer malware. The Arch Linux team is currently investigating the situation, and no timeline for restoring package adoption has been provided.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…