The Arch Linux project has temporarily disabled the package adoption feature in the Arch User Repository to combat a surge of malware [1, 3].
This move targets a critical vulnerability in the community-maintained archive where attackers were hijacking existing packages to distribute malicious code. Because the AUR is a primary source for software not found in the official repositories, a compromise here can expose thousands of users to system-level infections.
The security team took action after observing a wave of malicious package adoptions followed by compromised commits [2, 3]. These attacks allowed bad actors to take over the maintenance of legitimate packages and replace them with malware-laden versions [2, 5].
"Due to the current influx of malicious package adoptions and follow‑up commits made via the AUR, we are pausing adoption for now," the Arch Linux security team said [2].
The project described the situation as a surge in malicious takeovers of existing packages [3]. Reports indicate that this activity constituted a "third wave" of attacks occurring in June 2024, involving a Tor-backed Rust infostealer that bypassed previous defenses [6].
Package adoption is a feature that allows a new maintainer to take over an orphaned or abandoned package. By disabling this, the project prevents attackers from claiming ownership of neglected software to inject malicious updates [1, 3]. The project has not yet specified a date for when the feature will be restored, as they continue to mitigate the flood of malicious entries [3, 5].
“Arch Linux has temporarily disabled adoption of AUR packages after a surge in malicious takeovers.”
This incident highlights the inherent security risks of community-driven repositories that rely on trust-based ownership transfers. By disabling the adoption mechanism, Arch Linux is prioritizing system integrity over community convenience, signaling a shift toward more restrictive guardianship to prevent supply-chain attacks in the open-source ecosystem.


