• Sources: Arch Linux DevOps announcement, aur-general 2026-07-31, LWN, Arch Linux incident notice 2026-06-12, discussion
  • Summary: The Arch Linux DevOps team announced on the aur-general list on 2026-07-31 that adoption of orphaned AUR packages is disabled while the team works through an influx of malicious adoptions. LWN reports that the adopted packages carry a remote access trojan with a Tor command channel, citing analysis by Michael Taggart, and describes the account registration restrictions added after the June 2026 waves as ineffective against this one. The announcement states neither a package count nor a package list, and the mailing list posts that name affected package and binary pairs come from list participants rather than Arch staff. Official binary repositories are not implicated in anything verifiable from these sources.
  • Why it matters: AUR helpers run PKGBUILD build steps on the developer's own machine, so an adopted orphan package executes attacker code at build time rather than at install time, which makes reviewing PKGBUILD diffs before any rebuild the operative mitigation while adoption stays disabled.
  • Follow-up: Track whether adoption is re-enabled, and whether Arch publishes a package list or a post-incident notice on archlinux.org for this wave as it did on 2026-06-12.

send feedback on this story