Arch Linux Halts AUR Adoption After Third Wave of Malware Attack
Arch Linux disabled package adoption on the Arch User Repository on July 30 following a third sustained wave of malicious takeovers dubbed "Atomic Arch." The campaign began in late May when attackers started adopting orphaned packages and embedding compiled ELF binaries directly into build scripts, effectively bypassing the npm and JavaScript-based detection methods that caught the earlier waves. Despite Arch developers declaring the repository clean in mid-June after purging more than 1,900 compromised packages, the threat quickly escalated with obfuscated downloaders and static payloads that execute during the makepkg build phase. The ongoing crisis has exposed the fundamental tension between an open, community-maintained repository and supply-chain security, leaving adoption temporarily frozen while the ecosystem develops more robust trust and detection mechanisms.
Arch Linux Halts AUR Adoption After Third Wave of Malware Attack @ Linux Compatible
Arch Linux Halts AUR Adoption After Third Wave of Malware Attack
Arch Linux has halted package adoption on the Arch User Repository (AUR) as of July 30 due to a third wave of malware attacks, referred to as "Atomic Arch," which began in late May and has compromised over 1,900 packages. The attacks involve malicious actors adopting orphaned packages and embedding harmful compiled binaries within build scripts, circumventing prior detection measures. Despite efforts to purge compromised packages and declare the repository clean, the situation escalated with more sophisticated attack methods that bypass traditional scanning tools. The ongoing crisis highlights the challenges of securing an open-source repository while maintaining community contributions, leading to a temporary freeze on adoption and new account registrations until the issue is resolved
