Did you know we have a Forum? Come and say hi to the wider community!

The security situation with the Arch Linux AUR got a lot worse

| Last updated: 14 Jun 2026 at 7:40 pm UTC
By

Oh dear, the situation with the Arch Linux AUR got a fair bit worse since GamingOnLinux initially covered the malicious packages.

At the time the initial article was put up, there were a bit over 400 compromised packages on the Arch Linux Arch User Repository (AUR). That list of affected packages (source) rose quite sharply and checking again now there's nearly 2,000 noted. That's a lot of packages to be hit like this.

Later last night the attacks were reported to be continuing on "with obfuscated code", and another report in the early hours of this morning noting it's become "a little bit more elaborate". Not all of the packaging issues are as bad as the initial wave of trying to steal credentials, some are just adding ridiculous messages in Russian.

The AUR developers and maintainers are clearly going to need to rethink how the service is run. While it's a wonderful idea to let anyone come along and package extra apps and such if they're missing from Arch Linux repositories, anything left open in any way is going to cause problems. Especially so now in 2026, when Linux is clearly more popular than ever - anything Linux related like this is going to become a bigger target. And with AI bots too, making such a hit has become far easier.

At least some level of human review is going to be needed. Otherwise, this certainly won't be the last time we see the AUR having security problems.

Article taken from GamingOnLinux.com.
26 Likes
About the author -
author picture
I am the owner of GamingOnLinux. After discovering Linux back in the days of Mandrake in 2003, I constantly checked on the progress of Linux until Ubuntu appeared on the scene and it helped me to really love it. You can reach me easily by emailing GamingOnLinux directly. You can follow me personally on Mastodon [External Link].
See more from me
All posts need to follow our rules. Please hit the Report Flag icon on any post that breaks the rules or contains illegal / harmful content. Readers can also email us for any issues or concerns.
47 comments
Page: 3/3
  Go to:
seflasporin 1 day ago
User Avatar
  • New User
Quoting: GerarderloperSo far non of my AUR packages have been touched, but I am waiting for the dreaded updates for any of them to come where suddenly a 'new' maintainer appears out of nowhere...
This only affects orphaned PKGBUILDs. If yours all have maintainers then they'll be fine.
devland 1 day ago
User Avatar
Quoting: dibzWow, some easily offended folks in here

Anything that pulls source from something like github some jackass can compromise by having their keys stolen - or if they're just bored and feeling frisky.

So yes, modern development practices affect rolling distros more because they tend to use the latest and greatest all the time - which is not always great.
Again, the rolling release official repos of ARCH were not affected by the AUR hack. You're confusing two were different concepts based on what I can only assume is your disdain towards that particular OS.

Rolling release distros don't just pull from git straight into their official repos and call it a day. No distro does that.

Take the XZ compromise not all that long ago, which released a new "stable" compromised version that actually made it on to user systems - y'all know the problem commit was only about a month old? That's a crazy short timeline.
The AUR hack was found and actually fixed in under two weeks so that analogy really doesn't strengthen your position.
mercster 1 day ago
User Avatar
While it's a wonderful idea to let anyone come along and package extra apps and such if they're missing from Arch Linux repositories
No, it's not, and never has been. Arch is a clownshow, I've been saying it for years. It became the choice for newbies because it intentionally makes installing it laborious, so they feel like they're hacking the Gibson or something. "Hey look at me, I survived installing Arch Linux." Yeah, congrats, the list of things you typed in using a guide, and that you won't remember, are pretty impressive. Maybe it's a better idea to run a "newbie" (i.e. well engineered) distro like Ubuntu or Fedora after all. ¯\_(ツ)_/¯
Slaxer 2 hours ago
User Avatar
Quoting: mercsterArch is a clownshow, I've been saying it for years.
Arch is only a clownshow if you don't know what you're doing, and you go into it unaware of its DIY ethos. When I was a beginner, I didn't know what I was doing. I made mistakes, and I broke my installation a few times - but I've learned, and I had fun learning. I don't even remember the last time I experienced any problems on my Arch box, and if I do run into any problems again, it's not gonna matter cause I'll know how to fix it. I owe a lot of my Linux sysadmin skills from the experience I gained from using Arch.

So you downloaded a dirty package from the AUR? Now you've learned, and you won't do that again, right?

TL;DR - Arch is not a clownshow.
Jarmer 2 hours ago
User Avatar
Quoting: mercsterArch is a clownshow, I've been saying it for years. It became the choice for newbies because it intentionally makes installing it laborious, so they feel like they're hacking the Gibson or something. "Hey look at me, I survived installing Arch Linux." Yeah, congrats, the list of things you typed in using a guide, and that you won't remember, are pretty impressive. Maybe it's a better idea to run a "newbie" (i.e. well engineered) distro like Ubuntu or Fedora after all. ¯\_(ツ)_/¯
Wow this is one helluva comment. I think you deserve a gold star for getting SO many things wrong all at the same time! quite incredible really, I'm pretty impressed. Let's see, where shall we begin?

  • Arch is not a clownshow (lol who says stuff like this? I mean?)

  • Arch is not the distro of choice for newbies and never has been

  • Arch does not intentionally make installing it difficult

  • Fedora is not a newbie distro, are you confusing this with mint or something?


I'm pretty stunned by the Arch hate in this comments thread, and SO MUCH of it is just ignorant ranting that has no basis in reality. People can't seem to grasp the fact that the AUR is not in fact the distro itself, or are confused about what the AUR even is, or how Arch even functions, but still complain about it, or make up a bunch of nonsense like the above. Oof.
User Avatar
Quoting: JarmerI'm pretty stunned by the Arch hate in this comments thread, and SO MUCH of it is just ignorant ranting that has no basis in reality. People can't seem to grasp the fact that the AUR is not in fact the distro itself, or are confused about what the AUR even is, or how Arch even functions, but still complain about it, or make up a bunch of nonsense like the above. Oof.
There's been some odd stuff. To the point where I feel the need to note that while Arch is not my distro and not targeted at people like me and I am not likely to consider using it, I am nonetheless aware that it serves its purposes well and there are skilled people working hard on it and the AUR is not the same as the overall distro repository.
Slaxer 1 hour ago
User Avatar
Quoting: Jarmer
  • Arch is not a clownshow (lol who says stuff like this? I mean?)

Just replying to a guy that said that it was? K there bud. Chill out.

Edit: Actually, I owe you an apology. I misread the quote, and thought you were replying to me. Sorry about that. I owe you a beer.

Last edited by Slaxer on 17 Jun 2026 at 8:47 pm UTC
While you're here, please consider supporting GamingOnLinux on:

Reward Tiers: Patreon Logo Patreon. Plain Donations: PayPal Logo PayPal.

This ensures all of our main content remains totally free for everyone! Patreon supporters can also remove all adverts and sponsors! Supporting us helps bring good, fresh content. Without your continued support, we simply could not continue!

You can find even more ways to support us on this dedicated page any time. If you already are, thank you!
Login / Register