Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages
Geschrieben am 12-06-2026 - ⧖ 1.0 minArch contributors are cleaning up a malware incident in the AUR after suspicious updates appeared across several user-maintained packages.
Arch Linux’s AUR is experiencing a malware incident involving user-contributed packages with malicious commits that attempt to download npm-based payloads during installation.
The issue was first reported on the Arch Linux aur-general mailing list, where contributors are tracking affected packages in a dedicated thread. Cleanup efforts are ongoing, with malicious commits being removed and related accounts banned.
Importantly, this incident affects only the Arch User Repository, not the official Arch Linux package repositories.
In this case, suspicious changes to AUR packages added npm commands unrelated to the original software. Community reports indicate that malicious logic is triggered during installation, frequently involving npm packages such as atomic-lockfile.
[...] https://linuxiac.com/arch-linux-aur-malware-campaign-hits-multiple-user-contributed-packages/
Es sind aber nicht viele Pakete die betroffen sind. Nur grob geschätzt 500+; Tendenz steigend: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/
Als wäre Linux nicht schon Scheisse genug ^^