| Headlines |
| 2026-06-12 |
Arch Linux reports malicious incident in AUR repository |
 |
There is trouble in Arch's AUR (Arch User Repository). Reports started to come in yesterday about a new maintainer adopting some packages and adding malicious commits to them. The compromised packages now include a post-install script that installs atomic-lockfile, a package that appears to be able to extract some private data from the user's computer. Campbell Jones posted an update about the situation earlier today: "We are currently experiencing a high volume of malicious package adoptions and updates in the Arch User Repository. We are actively working to track down existing malicious commits and attempting to prevent additional malicious commits from being pushed. While this is happening, and while we work to create a more permanent solution, users may see issues with the following: creating new accounts on the AUR; pushing package updates; adopting or creating new packages. We continue to encourage all users of AUR packages to review all PKGBUILD and install script changes when updating, especially during this time. If you notice suspicious commits to a package that you use, please reach out to Arch staff via the aur-general mailing list with more information." A list of compromised packages is available here.
|
More headlines from this project
Back to News
|
|
| TUXEDO |

TUXEDO Computers - Linux Hardware in a tailor made suite Choose from a wide range of laptops and PCs in various sizes and shapes at TUXEDOComputers.com. Every machine comes pre-installed and ready-to-run with Linux. Full 24 months of warranty and lifetime support included!
Learn more about our full service package and all benefits from buying at TUXEDO.
|
| Star Labs |

Star Labs - Laptops built for Linux.
View our range including the highly anticipated StarFighter. Available with coreboot open-source firmware and a choice of Ubuntu, elementary, Manjaro and more. Visit Star Labs for information, to buy and get support.
|
|