CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Arch Linux supply chain attack spreads to 1,900+ AUR packages

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 173

As cited

Copy frozen at (site build).

breaches incidents

Risky Bulletin: Arch Linux supply chain attack spreads to 1,900+ AUR packages

More than 1,900 Arch Linux packages in the AUR (Arch User Repository) community portal were compromised in a supply chain attack over the weekend. The attacker exploited a feature allowing adoption of orphaned packages to gain maintainer access and inject a rootkit and credentials harvester. The attack affected approximately 10% of the AUR's 100,000 total packages.

Why it matters: Arch Linux users relying on AUR packages may have unknowingly installed malware; immediate verification and reinstallation of affected packages from trusted sources is critical.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary