Arch Linux has disabled new AUR account registrations following a large-scale malware campaign targeting the Arch User Repository. Over 1,500 packages were compromised in the first wave, with two additional waves following. The malware was traced to a malicious npm package called js-digest embedded in post-install scripts. Subsequent waves used obfuscation techniques, including splitting strings across literals to evade detection. The core Arch Linux repositories remain unaffected. Users are advised to review all PKGBUILD and install script changes before updating and report suspicious packages to the aur-general mailing list.

3m read timeFrom feed.itsfoss.com
Post cover image
Table of contents
What happened?What can you do?
3.9K Impressions