Arch Linux strengthens AUR security with new restrictions

  • The AUR has temporarily disabled package adoption to strengthen its security.
  • Arch Linux also reduces the period for considering a package orphaned from 90 to 30 days.
  • The measures come after an attack that compromised more than 1.500 packages from the community repository.

AUR and Malware

AURArch Linux's community repository, has temporarily disabled package adoption as a security measure following the serious malware incident discovered last JuneThe decision aims to prevent attackers from exploiting the orphan package adoption system again to distribute malicious code to users.

The measure is part of a series of changes that the Arch Linux project is implementing to strengthen the security of the AUR after one of the most significant supply chain compromise campaigns suffered by the repository.

AUR suspends package adoption after malware attack

The most significant change is the temporary disabling of the feature that allows adopting orphaned packages. The developers believe this mechanism was one of the main attack vectors used, in which the attackers gained control of numerous abandoned packages to introduce malicious modifications to their build scripts.

In addition to blocking adoptions, Arch Linux has reduced the period required for a package to be considered orphaned, from 90 to 30 days. The goal is to make it easier for legitimate maintainers to regain control of abandoned projects more quickly through new, stricter review procedures.

These measures come after the incident detected in June, when hundreds of AUR packages were initially compromised. As the investigation progressed, maintainers identified more than 1.500 packages affected by different waves of the attack, which required a manual review of a large number of packages and user accounts.

Although the issue affected only the AUR and not the official Arch Linux repositories, the project continues to recommend carefully reviewing PKGBUILD files before installing or updating software from the community repository, especially if the package has recently changed maintainers. The new restrictions aim to reduce the risk of similar attacks while permanent security measures are implemented.


Add as preferred source in Google