INFRA Signal 289 2 feeds carried it
Arch Linux disables AUR package adoption
Engineers pulling from AUR can no longer trust that a previously legitimate orphaned package remains safe, since attackers are actively hijacking them to deliver malware that exfiltrates data over Tor. The failure of the project's earlier mitigation—restricting new account registration—shows that community repository trust models are still vulnerable to this class of attack, and the adoption mechanism stays disabled indefinitely.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Attackers adopted orphaned AUR packages and injected updates containing a remote-access trojan that takes commands over Tor and uploads a wide range of user data.
A prior suspension of new account registration, reopened on July 13 with minor restrictions, failed to stop the malicious adoptions.
Package adoption in AUR is now disabled with no announced timeline for restoration, leaving all orphaned packages unadoptable.
THE CLUSTER