Or so it seems from the aur mailing list and they might be going after more common software now as this thread mentions that someone tried to delete librewolf-bin.
Dammit I use librewolf-bin!
shresth paul <shresthpaul133@gmail.com>
10:48 AM (2 hours ago)
to Claudia, aur-general
Hello,
Now the same thing happening from this account.
ueprpo35554d
Seems like the more we are reporting. The more they’re changing the account.
Thanks
SecByShresth
On Sun, 26 Jul 2026 at 15:55, shresth paul <shresthpaul133@gmail.com> wrote:
Hello Claudia/All,
Thank you so much, but again we're getting a lot of spams, they're coming in from the below mentioned account, seems like they're targeting deletion requests now.
ybnmaob2594j [1] filed a deletion request for librewolf-bin [2]:
Mr. President A Second Plane Has Hit The Boom(aur)er
https://www.youtube.com/watch?v=XJWqHmY-g9U
https://www.youtube.com/watch?v=072Nu54avdU
Thanks
SecByShresth
On Sun, Jul 26, 2026 at 5:13 AM Claudia Pellegrino <auerhuhn@archlinux.org> wrote:
Hi HurricanePootis,
> Within the past 7 minutes, I just got two orphan requests from spam
> accounts (zvbepb and xevdey):
Dealt with, thanks for the heads up!
Regards
Claudia
Now i have to build each release on my own 
Good thing Librewolf ships Flatpaks too! :3
I saw that puke icon just the other day but yah cannot find it when it is truly needed!
I’ve always used librewolf. do I just assume now my system is compromised?
I don’t think so, I am not assuming that.
Just a heads up is all.
inb4 Flatpak vs standard packaging flame war begins. I’m not starting it this time.
No you don’t.
Librewolf cryptographically signs the binaries shipped on the AUR so if someone actually managed to get that package deleted (unlikely) and replaced the binary with a malicious one, then it should be immediately apparent.
Also you should check the pkgbuilds for any unusual changes. If you don’t fancy doing that, then use the (slightly older) version in the chaotic AUR.
Edit: I’d like to think that the AUR wouldn’t accept an orphan/deletion request that’s just a 9/11 meme. Nothing to see here.
it’s only about the -bin for me
I don’t get it anyway. You can’t compare flatpak with system packages. Flatpaks are sandboxed, system packages usually aren’t. After the last AUR attack, I would always prefer flatpak over AUR packages, if they are verified developer packages. Even if flatpaks might get compromised, too.
I check PKGBUILD files for what exactly? The checksums? How the fuc- do I know that the checksum is valid? I go out and search for the binary checksum every single time there’s an update to the package? Might as well just, I don’t know, build it from source myself.
Whats this about a chaotic AUR–I have never heard this before.
I am new so whats the chaotic AUR?
What exactly is slightly older versions?
I will stop here because it’s obvious the flame wars will begin and I am not in the mood for one. Sucks that this is happening, but I can’t say I am entirely surprised.
Chaotic-AUR is Garuda’s repo of pre-built AUR packages. Basically, very common AUR packages are ran and then packaged up like standard old packages you can install without using an AUR helper.
What flame war?
I stopped flaming flat-packs, all I did was mention that I don’t like them.
I will try to stop mentioning it if it upsets you?
That pkgbuild pulls in a binary from Codeberg. The server shouldn’t change too often. If it does, then there should be a blogpost on the official website explaining the migration.
Aside from that, check for dependency changes and the usual stuff.
I don’t bother with the signing keys since yay automatically checks for that.
I feel the same way about the pkg build thing.
I AM learning though.
Maybe someone was not happy with Codeberg, and is trying to take revenge ?