AURpocalypse now: a look at the recent AUR attacks
The Arch User Repository (AUR) recently faced a series of malicious attacks where compromised accounts pushed malware-laden updates to users. In response, maintainers have temporarily disabled new user registrations while evaluating long-term security improvements for the community-driven platform.
Why it matters
This highlights the inherent security risks in community-maintained software repositories and the challenges of balancing open collaboration with supply chain integrity.
Welcome to LWN.net The following subscription-only content has been made available to you by an LWN subscriber. Thousands of subscribers depend on LWN for the best news from the Linux and free software communities. If you enjoy this article, please consider accepting the discount offer on the right. Thank you for visiting LWN.net! Special discount offer Subscribe to LWN now at the "professional hacker" level for at least six months, and you will receive a special discount of 25%. By Joe Brockmeier June 19, 2026 The Arch User Repository (AUR) has been subjected to a sustained attack recently. The attacker, or attackers, have spun up a series of new accounts then used them to adopt orphaned packages and push malicious updates that would install malware on users' systems. It is unclear how many users were compromised in the attack, but the maintainers were playing Whac-A-Mole for several days to respond to each newly compromised package. The project has turned off the AUR's new-user registration , for now, but it is unclear what its long-term response will be or if the AUR can be secured without major changes to its existing collaboration model.
The article provides a factual, technical report on a security incident without political or ideological framing.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in