
AURArch Linux's community repository, has temporarily disabled package adoption as a security measure following the serious malware incident discovered last JuneThe decision aims to prevent attackers from exploiting the orphan package adoption system again to distribute malicious code to users.
The measure is part of a series of changes that the Arch Linux project is implementing to strengthen the security of the AUR after one of the most significant supply chain compromise campaigns suffered by the repository.
AUR suspends package adoption after malware attack
The most significant change is the temporary disabling of the feature that allows adopting orphaned packages. The developers believe this mechanism was one of the main attack vectors used, in which the attackers gained control of numerous abandoned packages to introduce malicious modifications to their build scripts.
In addition to blocking adoptions, Arch Linux has reduced the period required for a package to be considered orphaned, from 90 to 30 days. The goal is to make it easier for legitimate maintainers to regain control of abandoned projects more quickly through new, stricter review procedures.
These measures come after the incident detected in June, when hundreds of AUR packages were initially compromised. As the investigation progressed, maintainers identified more than 1.500 packages affected by different waves of the attack, which required a manual review of a large number of packages and user accounts.
Although the issue affected only the AUR and not the official Arch Linux repositories, the project continues to recommend carefully reviewing PKGBUILD files before installing or updating software from the community repository, especially if the package has recently changed maintainers. The new restrictions aim to reduce the risk of similar attacks while permanent security measures are implemented.