I use malware, btw 😎
Arch should be stopped to be recommended to new users of Linux ASAP
Arch as far as I am aware has never been recommended to new users. Sure their is CachyOS and other variants. And on top of that AUR you shut read the build scripts. But I suppose not many people do that unfortunately.
more importantly, they don’t recommend that users use the AUR repository (that isn’t to say they are opposed to it). Some advice they have given is to review what the dependencies are before executing the package with an AUR helper or manually.
Just to make a point, there is a surplus of these non officially supported (from OS developers) repositories, such as the terra repository for fedora. It has the same vulnerability as AUR, and yet that is targeted for new users.
Much like how fedora doesn’t officially support Terra, arch doesn’t support AUR. There is a reason why it’s called AUR (arch user repository) over ASR (arch supported repository). AUR entails that it is not supported by arch.
It’s a trend between kids going for an “advanced” distro
You have to go download an AUR helper to even get into the AUR, it does not come by default on Arch systems. You have to actually do this to yourself to get the malware.
Lmao shut up
he’s right is he not?
Is anybody really recommending Arch to new users though?
Yeah, there’s a ton of people that recommend Cachy when it is really meant for tinkerers IMHO
I’m very tired of the rhetoric that Arch is only meant for tinkerers. If all you do is have plasma steam and a web browser it’s no more or less likely to break than any other distro. You could go your entire life without ever looking at the terminal.
And while yes this malware is a problem it is specifically in the aur, the arch user repository an unofficial repository not officially supported, just don’t use it. Unless you need a weird piece of software generally related to some type of specific hobby you’re unlikely to ever even want to look at it anyway.
I do agree with this in theory. I just don’t know many ‘normal people’ that are going to only ever require those three things. (Totally with you on the AUR bit)
Really? If anything I have the opposite problem all the normal people I’m aware of probably don’t even need steam just the web browser and plasma. Pretty much everything is in the web browser these days I mean they might want the dedicated discord client but that’s ultimately just a web browser in a box and will also work perfectly no AUR required
Man I feel like I dodged a bullet switching to Fedora right before this AUR fuckery started to happen…
Same. I was on Cachy for a few months but recently switched back to Fedora. I’m sleeping very peacefully.
You don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
Sure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.
I feel like when this pops up everyone freaks out and yells about how it’s proof the aur sucks and arch is doomed. Do you people randomly install GitHub repos without any due diligence? Do you click on random ads to download bake bean can cursors? There’s malware fuckin everywhere. Just do your due diligence and don’t get screwed. And if you do get malware, have a plan to make it irrelevant. Anyone who doesn’t do these things should in no way be using the AUR.
friends don’t let friends use the AUR
What’s the alternative?
😎 Debian 😎
Not rolling release
I only use official and flatpak, I wouldn’t even use flatpak if official had more.
Chaotic aur might be worth looking into if aur is what you want. Everything there is theoretically checked.
all they have to do is to check the damn diff, if that’s not easy for someone then they should stop using a computer altogether. I mean they could just click to random links on the internet right?
Tumbleweed stay winning
I do agree Tumbleweed is great. My distro of choice as well. But it can have its more obscure issues from time to time as well. No distro is perfect.
Adoptions are a mistake anyways. Remove unmaintained packages and block the name for several months.
For the record, those are all new packages (not orphaned packages being adopted). I assume more will come, we’ll clean those as soon as possible.
In the mean time stay vigilant, probably refrain from installing freshly pushed new packages from the AUR for now.
So wasn’t adoption in this case. Looks like instead they submitted a bunch of git/bin versions of existing packages.
Adoption of unmaintained packages to maintain them is not a mistake. The problem is the current implementation, not the idea behind it. It’s like saying the AUR is a mistake, because some people do malicious stuff.
They should find a better solution, like adoption shouldn’t be granted to everyone without question, especially new accounts who didn’t maintain anything before. Mass adoption shouldn’t be granted automatically (limit rate), in example 1 package adoption per day and if someone wants more, admins or moderators need to approve. And updates of newly adopted packages should wait a day.
Also the AUR helpers should do a better job. Always ask if a new adopted package should be updated and give a warning the maintainer changed.
They should find a better solution
Who’s “they”? Because it’s not Arch. Arch doesn’t want to have anything to do with AUR, and neither does any of the Arch-derived distros. They’re all perfectly happy taking advantage of it, of course, but not the responsibility.
Who’s “they”? Because it’s not Arch. Arch doesn’t want to have anything to do with AUR, and neither does any of the Arch-derived distros. They’re all perfectly happy taking advantage of it, of course, but not the responsibility.
Where did you got this nonsense from? What do you mean “they are not Arch”? The AUR is managed and operated by the Archlinux team. As the packages are community-driven content, they cannot guarantee and give support, because it is not their package. But they are still managing and supporting the AUR itself.
- https://archlinux.org/news/active-aur-malicious-packages-incident/ from 2026-06-12 is an official message on the main Archlinux website (there is no new post about the current situation).
- from https://archlinux.org/people/package-maintainers/ : Campbell Jones is an AUR Moderator
- from https://archlinux.org/people/support-staff/ : Andrea Denisse Gómez-Martínez is an AUR Packager, Robin Candau is an AUR Moderator
it’s not managing, as you seem to imply, it’s just hosting.
Arch hosts the AUR repository, the maintenance of the packages is on the developers who developed the package.
If someone sneaks in spyware or malware inside the makepkg, that isn’t arch’s fault, that’s the maintainers fault of the makepkg.
If someone sneaks in spyware or malware inside the makepkg, that isn’t arch’s fault, that’s the maintainers fault of the makepkg.
I don’t think that anyone argued otherwise.
I even said it in the very reply you are replying:
The AUR is managed and operated by the Archlinux team. As the packages are community-driven content, they cannot guarantee and give support, because it is not their package.
And you’re gonna see the Arch team wash their hands of the whole thing, like they did in the past whenever the AUR was in trouble.
That’s not real ownership.
Do you have any sources, links or evidence for your statements?
Is the current state of the AUR, despite the previous waves of attacks, and its troubled history, not evidence enough? The Arch team has never made the AUR a priority and I don’t see why they would start now.
The way I see it there are three possibilities:
- They do nothing.
- They shut it down.
- They give it up for adoption.
What is not going to happen is the Arch team putting time and effort into overhauling the AUR.
No way to prevent this, says only repo where this regularly happens
I mean, nobody is saying there is no way to prevent this, and I would hardly say that “twice” can be cathegorized as regularly.
Also I find this of extremely bad taste as you seem to compare this to school shootings, with literal children deaths. I would say that a few thinkerers getting pwned from their claude tokens is a couple orders of magnitude less serious.
Not the only repo, see: npm
Npm doesn’t let you easily take over packages you don’t own.
but does let you take over their maintainers’ accounts (through poor security) and easily poison them
Not more easily than anything else.
Besides all the other non infected ways to install the software, there is a way to prevent this: Just read the AUR package before install and don’t trust blindly any new maintainer.
It’s metaphysical approach to security. Enshrined rules that can’t be enforced don’t define user’s behavior.














