Risky Bulletin Newsletter
June 15, 2026
Risky Bulletin: Arch Linux supply chain attack spreads to 1,900+ AUR packages
Presented by
News Editor
More than 1,900 Arch Linux packages have been hijacked over the weekend as part of a massive supply chain attack designed to infect users with a rootkit and a credentials harvester.
The attacker(s) targeted Arch Linux packages hosted on the AUR portal, an unofficial repository of Arch packages created by the community. The portal hosts a massive 100,000 entries, but almost a tenth have been abandoned by their maintainers in what AUR calls "orphaned packages."
The attack exploited an AUR mechanism that allowed the hacker to "adopt" the abandoned packages and become a maintainer.