---
title: "News: Active AUR malicious packages incident"
url: https://daily.dev/posts/news-active-aur-malicious-packages-incident-0vefqnwsb
source_url: https://archlinux.org/news/active-aur-malicious-packages-incident
type: article
source: "Arch Linux"
published: 2026-06-12T19:00:35.055Z
updated: 2026-06-12T19:01:23.650Z
tags: ["cyber", "linux"]
reading_time: 1
upvotes: 4
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# News: Active AUR malicious packages incident

**[Arch Linux](https://daily.dev/sources/archlinux)** · 1 min read · 4 upvotes · 0 comments

## Summary

The Arch User Repository (AUR) is currently under an active attack involving malicious package adoptions and updates. The Arch team is working to identify and remove malicious commits while preventing further ones. As a precaution, some AUR functions may be restricted, including account creation, package updates, and package adoption. Users are strongly advised to carefully review all PKGBUILD and install script changes before updating, and to report any suspicious commits to Arch staff via the aur-general mailing list.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://archlinux.org/news/active-aur-malicious-packages-incident>

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#linux](https://daily.dev/tags/linux)

[View this post on daily.dev](https://daily.dev/posts/news-active-aur-malicious-packages-incident-0vefqnwsb)
