Arch Linux locks down AUR signups amid wave of malicious commits
ID: b1e0e36a-8d0b-5bfd-8ac5-2eb9c25020cb
STIX ID: report--b1e0e36a-8d0b-5bfd-8ac5-2eb9c25020cb
Feed Name: The Register (Security)
Threat Score
A wave of malicious commits targeted the Arch User Repository (AUR), compromising hundreds to over a thousand community packages and prompting Arch to disable new account registrations while maintainers clean up; the malicious packages attempted to introduce hostile JavaScript/npm dependencies, though the core Arch distribution remained unaffected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
