<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/malicious-aur-packages-removed-from-arch-linux-gbnogtqps" -->

---
title: Malicious AUR Packages Removed from Arch Linux | daily.dev
description: Malicious packages containing Chaos Remote Access Trojan were discovered in Arch Linux&#x27;s AUR, targeting browser applications like Firefox and Zen. The...
canonical: https://daily.dev/posts/malicious-aur-packages-removed-from-arch-linux-gbnogtqps
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Malicious AUR Packages Removed from Arch Linux | daily.dev
og:description: Malicious packages containing Chaos Remote Access Trojan were discovered in Arch Linux&#x27;s AUR, targeting browser applications like Firefox and Zen. The...
og:url: https://daily.dev/posts/malicious-aur-packages-removed-from-arch-linux-gbnogtqps
og:image: https://api.daily.dev/og/posts/gbnOGTqPS.png
og:image:alt: Malicious AUR Packages Removed from Arch Linux
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malicious AUR Packages Removed from Arch Linux

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 2 upvotes · 0 comments

## Summary

Malicious packages containing Chaos Remote Access Trojan were discovered in Arch Linux's AUR, targeting browser applications like Firefox and Zen. The compromised packages allowed attackers to execute commands and harvest data through scripts downloaded during installation. The Arch team quickly removed the packages and banned the responsible user, but the incident highlights security risks in community-driven repositories and emphasizes the need for careful package verification before installation.

## Content

Recently, the Arch Linux community faced a significant security concern as malicious packages were discovered in the Arch User Repository (AUR). These compromised packages included `firefox-patch-bin`, `librewolf-fix-bin`, and `zen-browser-patched-bin`, which were found to contain remote access trojans, specifically Chaos Remote Access Trojan (RAT).

The malware allowed attackers to execute commands, create reverse shells, and harvest data by downloading scripts from GitHub during package installation. These packages, claimed to be patches for browsers like Firefox and Zen, were distributed through Reddit by compromised accounts. Once the community identified the threat, the Arch Linux team acted quickly, removing the packages and banning the responsible user.

Although the malicious packages were swiftly removed from the AUR, this incident serves as a critical reminder of the security trade-offs associated with using community-driven repositories such as AUR. While they offer access to a vast array of Linux applications, the open nature allows for the potential distribution of malware due to limited initial oversight.

As Linux desktop adoption increases, users should exercise caution by diligently inspecting AUR package builds before installation and minimizing usage of user-contributed repositories where possible. Verifying sources and ensuring the authenticity of packages can help mitigate such risks.

For those who installed the compromised packages, it's advised to delete and reinstall clean versions to protect personal data and system integrity.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/malicious-aur-packages-removed-from-arch-linux-gbnogtqps)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Malicious AUR Packages Removed from Arch Linux","url":"https://daily.dev/posts/malicious-aur-packages-removed-from-arch-linux-gbnogtqps","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/malicious-aur-packages-removed-from-arch-linux-gbnogtqps"},"datePublished":"2025-07-21T01:47:08.590Z","dateModified":"2025-07-22T17:48:27.011Z","description":"Malicious packages containing Chaos Remote Access Trojan were discovered in Arch Linux's AUR, targeting browser applications like Firefox and Zen. The...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/563750e7c854dbbf562981d50ea548ef?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/563750e7c854dbbf562981d50ea548ef?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/malicious-aur-packages-removed-from-arch-linux-gbnogtqps","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,linux,malware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Malicious AUR Packages Removed from Arch Linux"}]}
```

