As cited
Copy frozen at (site build).
breaches incidents
Risky Bulletin: Arch Linux supply chain attack spreads to 1,900+ AUR packages
More than 1,900 Arch Linux packages in the AUR (Arch User Repository) community portal were compromised in a supply chain attack over the weekend. The attacker exploited a feature allowing adoption of orphaned packages to gain maintainer access and inject a rootkit and credentials harvester. The attack affected approximately 10% of the AUR's 100,000 total packages.
Why it matters: Arch Linux users relying on AUR packages may have unknowingly installed malware; immediate verification and reinstallation of affected packages from trusted sources is critical.
- Source published
- First seen by Cybersecurity Tracker