Arch Linux Disables AUR Package Adoption Amid Malicious Takeovers

The Arch Linux team has suspended package adoption in the AUR while it investigates malicious adoptions and follow-up commits.

Arch Linux has temporarily disabled package adoption in the Arch User Repository following a surge in malicious takeovers and harmful commits.

Robin Candau, on behalf of the Arch Linux DevOps team, announced the restriction on July 30. Package adoption will remain unavailable while the team handles the situation. No estimate has been given for when the feature will return.

To clarify, in the AUR, packages with maintainers who have stepped down can be marked as orphaned. Another registered user can adopt the package, become its maintainer, and push updated build instructions. While this helps keep abandoned packages alive, it also allows attackers to take control of trusted package names and replace their contents with malicious changes.

Reports on the AUR mailing list on July 30 described orphaned packages being adopted and modified so their source arrays downloaded unfamiliar binary files. The activity affected multiple packages and continued through newly created accounts after earlier ones were banned.

Importantly, Arch Linux has disabled only the adoption mechanism, rather than placing the entire AUR into read-only mode. Existing maintainers can still work on their packages, but users trying to adopt an orphaned package must wait until the restriction is lifted.

The Arch team is asking community members to report suspicious adoption events or commits that have not yet been addressed. Users should also be cautious when installing or updating AUR packages and inspect changes to PKGBUILD, install scripts, source URLs, and any new binary downloads before proceeding.

The latest activity follows a larger AUR security incident disclosed by Arch Linux on June 12. The project reported a high volume of malicious package adoptions and updates and warned that account creation, package submissions, updates, and adoptions could be affected while mitigations were introduced.

Importantly, just to be clear, the incident has nothing to do with Arch Linux’s official repositories. The AUR is a community-operated collection of build scripts rather than an officially supported binary repo by the Arch team, so devs have long advised users to review package contents before building anything obtained from it.

For now, users can continue installing and updating AUR packages. Arch Linux will publish a follow-up announcement once the package adoption feature is restored.

Bobby Borisov

Bobby Borisov

Bobby, an editor-in-chief at Linuxiac, is a Linux professional with over 20 years of experience. With a strong focus on Linux and open-source software, he has worked as a Senior Linux System Administrator, Software Developer, and DevOps Engineer for small and large multinational companies.

6 Comments

  1. IAmHugh

    If I don’t miss my guess anyone anywhere can adopt a orphaned repo, right? Is there any way to limit that adoption to only members on the Arch forums. Members that have been on the forum for say at least a full year?

  2. Josef

    Flatpak agents, no one is forcing you to use Arch/Aur. Don’t worry about the Aur maintainers not being able to handle it.

  3. LibsOfTech

    AUR is, by name, Arch User Repository, not part of the Arch’s main repositories. Software for users, by users. Dunno why you think it’s going to ruin Arch adoption rate.

  4. Philippe

    AUR will continue to pose problems as long as its access is not secured.

    Although it was created to help users, AUR now ruins Arch in terms of security and becomes a barrier to Arch adoption by people.

    In my opinion, we had better close it permanently.

    1. Thomas

      Agreed. The amount of malicious packages that have been found is absurd. People are to lazy to use more trustworthy sources as long as it exist.

      1. IAmHugh

        Tomas not completely accurate. PLENTLY of us run across a piece of software we want and the AUR happens to be the only place it’s available. Personally I find the lazy ones to be those that don’t completely package their apps and add them to a repository that is checked.

Leave a Reply

Your email address will not be published. Required fields are marked *