- Sources: aur-general announcement, aur-general archive, BleepingComputer report, HN discussion
- Summary: The Arch Linux DevOps team announced on the aur-general mailing list that package adoption in the AUR was disabled on 2026-07-30, and then that all pushes to the AUR were disabled on 2026-08-01, after a wave of malicious takeovers of orphaned packages. The first-party announcement names neither the affected packages nor a count. BleepingComputer relays a community tracker putting the scale at roughly 200 packages, states that the figure is not independently confirmed, and no full list has been published. The reported malware behaviour is a poisoned PKGBUILD build step whose second stage collects SSH keys, cloud and AI service API keys, and password manager data, and that behaviour comes from third-party analysis rather than from Arch.
- Why it matters: An AUR helper builds and runs PKGBUILD code as the invoking user, so a poisoned build step runs on the developer's own machine, and the reported second stage takes credentials from exactly that machine.
- Follow-up: Track whether Arch publishes a list of affected packages and when pushes are restored.
send feedback on this story