Article may be outdated

This article is 61 days old. Some details may have changed since publication.

Hacker News·3 min read·medium

Arch Linux disables AUR package adoption

D
database64128
✦AI Summary

Arch Linux has disabled the adoption of orphaned packages in the Arch User Repository (AUR) following a surge in malicious activity. Attackers have been using compromised accounts to inject remote-access trojans into legitimate software packages.

Why it matters

This highlights the security vulnerabilities inherent in community-maintained software repositories and the ongoing challenge of supply chain attacks in open-source ecosystems.

✦Dive DeeperCreate a free account to unlock

The Arch Linux DevOps team has announced that adoption of orphaned packages in the Arch User Repository (AUR) has been disabled due to " the current influx of malicious package adoptions and follow-up commits made via the AUR ". Michael Taggart has posted a brief analysis of the malware being added to a long list of packages in this round of attacks. The payload appears to be an remote-access trojan (RAT) that takes commands over the Tor network and attempts to upload a wide range of user data.

The project had suspended new account registration in June. That followed a campaign in which an attacker or attackers created new accounts to adopt orphaned packages and push malicious updates to them that would install malware on user systems. AUR registration was reopened on July 13 after the DevOps team added some minor, and apparently ineffective, restrictions on creating new accounts.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in