Arch Linux temporarily disabled package adoptions in the Arch User Repository (AUR) after maintainers reported another wave of malicious package activity affecting dozens of packages. Reports highlighted suspicious adoptions and package changes tied to entries including i915-sriov-dkms, rtk-git, boringssl-git/hasher, archutil/linter, warp-terminal-git, weather-display, and astro-box, prompting the project to investigate and contain the abuse.
Community members had already begun flagging seemingly malicious AUR packages in public forums, asking where to report them as concerns spread among Arch users. The latest incident follows a previous large-scale AUR abuse case involving more than 1,500 malicious packages, and Arch maintainers urged users to stay vigilant and report suspicious package adoptions and comments while mitigations remain in place.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
Arch Linux disabled every package push in the AUR as a broader containment measure during the ongoing malware wave. This goes beyond the earlier step of temporarily halting package adoptions.
A GitHub Gist documented a stripped Rust ELF sample tied to the AUR campaign, detailing its infostealer, RAT, and SSH worm behavior, persistence methods, anti-analysis checks, Tor-based encrypted C2, and credential and wallet theft capabilities. The analysis also published concrete IOCs including SHA-256 06c857c8ca798d50c765b4de39e6c4f272ecb57bc8316a8ed4c0fdf02fb59502 and an embedded X25519 server public key.
IFIN reported that the latest malicious AUR campaign began on July 29 with the openconnect-sso package and analyzed it as a two-stage malware chain. The attack used a loader that installed persistence and fetched a Rust-based Linux infostealer over Tor, with credential theft, remote administration, and SSH worm capabilities.
In June 2026, attackers took over abandoned AUR projects while preserving their names and histories, then modified PKGBUILD files so builds would download and execute malware. The campaign reportedly affected more than 400 AUR packages and distributed a Linux rootkit and an infostealer.
In response to the ongoing malicious adoption activity, the Arch Linux team temporarily disabled package adoptions in AUR while it investigates and mitigates the issue. The team also urged users to report suspicious adoption events and comments.
Arch Linux's AUR was reported to be facing another wave of malicious package activity, this time involving malicious package adoptions affecting dozens of packages such as i915-sriov-dkms, rtk-git, boringssl-git/hasher, archutil/linter, warp-terminal-git, weather-display, and astro-box.
A Reddit post in r/archlinux raised concern about a seemingly malicious Arch User Repository package and asked where it should be reported, indicating public discovery of suspicious package activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
14 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceruntimewire.com
Open sourcephoronix.com
Open sourcexakep.ru
Open sourcelists.archlinux.org
Open sourcegist.github.com
Open sourcelists.archlinux.org
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.