AUR Suspends Orphan Package Transfers After Attack

The Arch Linux Project announced that it has ceased the transfer of orphan packages to new maintainers in the AUR (Arch User Repository) due to a recent surge in attacks aimed at inserting malicious code into unattended packages. The attackers took advantage of the AUR’s feature allowing adoption of orphaned packages to insert malicious code.

Incidents on July 30 and 31 in the AUR uncovered substitutions of benign packages with 70 packages containing malicious changes. The malicious components included a Trojan for remote access, execution of commands downloaded via the Tor network, and sending confidential data found on the victim’s system to an external server, such as keys from cryptocurrency wallets and data from password managers.

The Arch Project plans to reinstate the ability to transfer support after implementing measures to prevent such attacks. Following a previous attack on June 15, the project had suspended new account registrations for the AUR repository but resumed them on July 13 with mandatory email verification.

/Reports, release notes, official announcements.