www.securityweek.com 6/16/2026, 11:30:24 AM · external

Arch Linux halts AUR signups after 1500 package supply attack

Arch Linux halts AUR signups after 1500 package supply attack
CyberSIXT Evidence Panel
Primary Source archlinux.org

ARCH Linux has suspended new account registrations on the Arch User Repository (AUR) due to a significant supply chain attack, known as Atomic Arch, which involves over 1,500 malicious packages. The attack began with modifications to abandoned packages that execute harmful NPM code upon installation. Attackers have shifted tactics to avoid detection, employing tools like eBPF for persistent malware that conceals processes and credentials.

Arch Linux is currently working to identify and eliminate malicious commits, advising users that any compromised system should be rebuilt from clean media and all credentials rotated.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline