AUR Attacked - again

New Attack Puts Arch’s AUR Into Lockdown… Again

See this:

And no, the AUR is not “in lockdown”. Adopting packages is disabled.

A thread regarding this already exists.

This thread should probably be locked.

Updating packages was disabled later too.

Had a AUR update within the last 2 hours.

Maintainer can’t update anything in the AUR, users can still download.

See: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/message/YPJ3FQYJTJXXY3RUXCYLMHUKHLIUNVFF/

I see, thanks

This second AUR wave is still unfolding — here’s how you can help

For those following the second AUR attack (late July, separate from June’s incident) — the first confirmed package is openconnect-sso, and as of the last update from the people tracking it, new malicious commits were still being found. It’s not a closed, finalized list yet, unlike June’s.

I’ve added openconnect-sso to archcanary’s community-reports list (picked up automatically on your next archcanary --refresh), but this is exactly the kind of situation where more eyes genuinely helps — if you spot a suspicious adoption or commit, or come across a package that looks compromised, there’s
a low-friction way to report it:

https://github.com/musqz/archcanary/blob/master/CONTRIBUTING.md

Two ways, whichever’s easier:

  • No git needed: fill out the report form with the package name and a link to whatever convinced you it’s suspicious.
  • Comfortable with git: add the name to lists/community_reports.txt and open a PR.

Either way, just needs something concrete linked (an AUR comment, a mailing-list post, a PKGBUILD diff, a writeup) — reports get reviewed by hand before merging, not auto-added.

I wonder why someone would attack arch, it’s linux that not many users use. 4-5% of the users on the world are using linux. Why attack such a small group ?

The only reason i can think of is because of a failed arch install :joy:

It’s probably a good idea to lock this thread. Or merge it to one of the others.

  • Carrying on a conversation here, especially about Archcanary, is just going to get confusing.

  • There is already an Archcanary thread:

  • There is already an AUR attack thread:

Everything has already been said in this thread. Please check out the relevant ones.