9
submitted 4 hours ago by halm@leminal.space to c/archlinux@lemmy.ml

I haven't heard a peep about the security status of AUR since the headlines about malware injections into thousands of packages. I've ensured that none of my installed software is affected by the attack (to the best of my ability), but I've held off on my regular yay -Syu since then. What has you all done to keep your machine updated but clean?

And is there any update from AUR maintainers that the situation is under control? Most of my installed AUR packages simply don't exist in the official Arch repos, so if not I'd have to look for other sources.

you are viewing a single comment's thread
view the rest of the comments
[-] Ooops@feddit.org 4 points 4 hours ago* (last edited 4 hours ago)

Those headlines were the usual "mention (seemingly) big numbers without context"-bullshit. You can easily look up the actual amount of packages in the AUR...

They also did not "inject malicious code into AUR packages" because of some insecurity that needed fixing. They simply took over orphaned packages then modified them.

So actual reality boils down to:malicious actors took over a miniscule amount of AUR packages with so little public interest nobody even maintained them. And the AUR is as secure as it ever was. Which means not very secure at all because it's public community content without any vetting. So look up the package and actually read the PKGFILE. Just as Arch is vocally warning you.

99.9% of changes are version numbering, checksum and rarely slight dependency changes. There is no chance anyone affected by a long orphaned package that got taken over and modified did ever read that one stupid file of just a few lines (or just the dif provided by several AUR helpers automatically).

[-] Telorand@reddthat.com 2 points 2 hours ago* (last edited 2 hours ago)

They also did not "inject malicious code into AUR packages" because of some insecurity that needed fixing. They simply took over orphaned packages then modified them.

I agree, but I wanted to clarify this point for anyone: they didn't "take over orphaned packages" themselves, they took over the individual install processes, provided by the AUR for packages, that have likely been abandoned by the maintainers. The AUR doesn't host the actual code for software itself; it's just a set of instructions that tells the client where to grab code from and what to do with it.

this post was submitted on 26 Jul 2026
9 points (90.9% liked)

Arch Linux

9870 readers
34 users here now

The beloved lightweight distro

founded 6 years ago
MODERATORS