9 Articles
9 Articles
The Arch User Repository (AUR) has become the target of a large-scale malware campaign. Attackers took over numerous orphaned package descriptions and added malicious components and released manipulated updates. The Arch Maintainers reacted with the removal of affected packages as well as blocking suspicious accounts. A mechanism has been exploited that allows users to take over unmaintained packages.
Arch Linux stops re-registration in the AUR repository after a massive wave of manipulated software packages through the Atomic Arch campaign. Those responsible for the Linux distribution Arch Linux have temporarily suspended the re-registration of user accounts for the Arch User Repository (AUR). The reason for this is a coordinated supply chain attack wave under the name Atomic Arch. The community-based repository allows users to provide their…
AUR Registrations Blocked Amid Ongoing Malware Mess
Arch has evidently stopped new AUR registrations for the time being while maintainers scrub malware and users debate how to harden the popular community repository. The post AUR Registrations Blocked Amid Ongoing Malware Mess appeared first on FOSS Force.
Atomic Arch Supply Chain Attack Hits Arch Linux AUR With 1,500 Malicious Packages
A large-scale Linux supply chain attack has hit the Arch User Repository, exposing how quickly community package ecosystems can be turned into malware delivery networks when trust, automation and abandoned projects collide. The campaign, now tracked by researchers as Atomic Arch, began last week and had pushed more than 1,500 malicious packages into AUR by June 11. AUR is the community-maintained software hub used by Arch Linux users to share PK…
Russian Spam and Profanities Are Now Plaguing the Arch Linux AUR
The Arch Linux User Repository "AUR" is facing another issue just days after more than 1,500 packages were found carrying malware. According to Phoronix, over 70 AUR packages have reportedly been modified to insert Russian spam and profane messages into users' shell configuration files. From the rep...

Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium



