Patreon Logo Support us on Patreon to keep GamingOnLinux alive. Alternatively, you can donate through PayPal Logo PayPal.

The security situation with the Arch Linux AUR got a lot worse

By -
Last updated: 14 Jun 2026 at 7:40 pm UTC

Oh dear, the situation with the Arch Linux AUR got a fair bit worse since GamingOnLinux initially covered the malicious packages.

At the time the initial article was put up, there were a bit over 400 compromised packages on the Arch Linux Arch User Repository (AUR). That list of affected packages (source) rose quite sharply and checking again now there's nearly 2,000 noted. That's a lot of packages to be hit like this.

Later last night the attacks were reported to be continuing on "with obfuscated code", and another report in the early hours of this morning noting it's become "a little bit more elaborate". Not all of the packaging issues are as bad as the initial wave of trying to steal credentials, some are just adding ridiculous messages in Russian.

The AUR developers and maintainers are clearly going to need to rethink how the service is run. While it's a wonderful idea to let anyone come along and package extra apps and such if they're missing from Arch Linux repositories, anything left open in any way is going to cause problems. Especially so now in 2026, when Linux is clearly more popular than ever - anything Linux related like this is going to become a bigger target. And with AI bots too, making such a hit has become far easier.

At least some level of human review is going to be needed. Otherwise, this certainly won't be the last time we see the AUR having security problems.

Article taken from GamingOnLinux.com.
7 Likes
About the author -
author picture
I am the owner of GamingOnLinux. After discovering Linux back in the days of Mandrake in 2003, I constantly checked on the progress of Linux until Ubuntu appeared on the scene and it helped me to really love it. You can reach me easily by emailing GamingOnLinux directly. You can follow me personally on Mastodon [External Link].
See more from me
All posts need to follow our rules. Please hit the Report Flag icon on any post that breaks the rules or contains illegal / harmful content. Readers can also email us for any issues or concerns.
5 comments

Slaxer 59 minutes ago
User Avatar
Uh oh.
CharlieTheMadHatter 43 minutes ago
User Avatar
It's a grim reminder that one should ALWAYS check the PKGBUILD files.

If you haven't, it's about time to start!
Chrisznix 17 minutes ago
User Avatar
Damnit, i had minitube installed, but not started it for months... fresh install with full password rotation, i guess?
mattaraxia 12 minutes ago
User Avatar
The problem is they can't rethink it without essentially killing it.

The near complete lack of oversight and controls is basically the AUR's one feature that distinguishes it from everything else out there.

Last edited by mattaraxia on 14 Jun 2026 at 8:46 pm UTC
seflasporin 12 minutes ago
User Avatar
  • New User
Calling it "obfuscated code" is a pretty large exaggeration. They're just using string concatenation to make it the text less human readable, it's not hiding what the instructions actually do. If anything this makes it more noticeable.
While you're here, please consider supporting GamingOnLinux on:

Reward Tiers: Patreon Logo Patreon. Plain Donations: PayPal Logo PayPal.

This ensures all of our main content remains totally free for everyone! Patreon supporters can also remove all adverts and sponsors! Supporting us helps bring good, fresh content. Without your continued support, we simply could not continue!

You can find even more ways to support us on this dedicated page any time. If you already are, thank you!
Login / Register