New Attack Puts Arch’s AUR Into Lockdown… Again
See this:
And no, the AUR is not “in lockdown”. Adopting packages is disabled.
A thread regarding this already exists.
This thread should probably be locked.
Updating packages was disabled later too.
Had a AUR update within the last 2 hours.
Maintainer can’t update anything in the AUR, users can still download.
I see, thanks
This second AUR wave is still unfolding — here’s how you can help
For those following the second AUR attack (late July, separate from June’s incident) — the first confirmed package is openconnect-sso, and as of the last update from the people tracking it, new malicious commits were still being found. It’s not a closed, finalized list yet, unlike June’s.
I’ve added openconnect-sso to archcanary’s community-reports list (picked up automatically on your next archcanary --refresh), but this is exactly the kind of situation where more eyes genuinely helps — if you spot a suspicious adoption or commit, or come across a package that looks compromised, there’s
a low-friction way to report it:
https://github.com/musqz/archcanary/blob/master/CONTRIBUTING.md
Two ways, whichever’s easier:
- No git needed: fill out the report form with the package name and a link to whatever convinced you it’s suspicious.
- Comfortable with git: add the name to lists/community_reports.txt and open a PR.
Either way, just needs something concrete linked (an AUR comment, a mailing-list post, a PKGBUILD diff, a writeup) — reports get reviewed by hand before merging, not auto-added.
I wonder why someone would attack arch, it’s linux that not many users use. 4-5% of the users on the world are using linux. Why attack such a small group ?
The only reason i can think of is because of a failed arch install ![]()
Everything has already been said in this thread. Please check out the relevant ones.