Arch Linux continues to struggle with a large-scale malware wave in its user repository AUR (Arch User Repository). This is currently literally flooded with malware. The attack continues and becomes more sophisticated.
After the developers behind the Linux distribution initially assumed that they had brought the security incident under control with more than 1,500 affected packages in which malicious code was integrated, further manipulated code submissions have now been discovered. The new wave of attacks is considered to be more technically sophisticated because the malicious functions were deliberately concealed, the magazine reports Phoronix.
A few days ago it became known that hundreds of packages in the AUR maintained by the community had been tagged with malicious code. While there was initially talk of around 400 compromised packages, over the course of the investigation the number rose to around 900 and ultimately to at least 1,579. According to the Arch Linux developers, all known malicious changes have now been removed from the repository. However, they noted that even this number may not capture all infected packages.
But just one day after the supposed cleanup, new cases appeared. A developer with the pseudonym “a821” reported additional compromised AUR packages. Among other things, various Node.js components, a package for Plasma 6 applets, Firefox-related extensions, the Aura browser, extensions for LibreWolf, a plug-in for NeoVim and other software packages were affected. The suspicious changes were removed after a short time.
A little later, security researcher Nicolas Boichat discovered additional manipulated packages. He used a locally operated AI model based on Gemma E2B to identify suspicious code. According to him, the new malicious code variants were significantly more sophisticated than the attacks previously discovered. In particular, the harmful commands relating to the Bun tool were so obscured that their actual function was difficult to recognize.
The incident once again raises questions about the security of the AUR. Unlike the official Arch Linux package sources, the repository is maintained by users who can provide their own software packages there. Given the repeated findings, some observers are calling for additional protective measures or even a temporary shutdown of the service until more effective security controls can be put in place. Meanwhile, the Arch Linux developers are continuing their investigations.
Research Snipers is currently covering all technology news including Google, Apple, Android, Xiaomi, Huawei, Samsung News, and More. Research Snipers has decade of experience in breaking technology news, covering latest trends in tech news, and recent developments.
GameStop does not see itself under pressure from the foreseeable end of physical PlayStation games.…
An upcoming Ubuntu kernel update brutally slows down AMD GPUs: The update to version 7.0.0-28.28…
The luxury brand Caviar is celebrating the 2026 World Cup with exclusive special editions. The…
A patent that has surfaced suggests that Nintendo could be working on a universal dock…
The dates for all upcoming sales on Valve's gaming platform Steam in the first half…
Spotify is unlocking a previous premium feature for all users. From now on, managed user…
View Comments