Pushes to arch AUR are suspendended right now.
Urgent Notice: Arch User Repository (AUR) Push Suspension
Date: August 1, 2026
From: Robin Candau (Antiz) on behalf of the Arch Linux DevOps team
⚠️ Security Alert: Malicious Activity Detected
The Arch Linux DevOps team has identified a significant surge in security threats targeting the AUR. Specifically, there has been an influx of malicious package adoptions followed by the submission of harmful commits.
To mitigate this risk, the team has implemented the following restrictions:
"Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation."
Current System Status
The restriction level has escalated since the initial announcement:
| Feature | Status | Note |
|---|---|---|
| Package Adoption | ❌ Disabled | Prevented to stop account takeovers |
| Package Pushes | ❌ Disabled | Total suspension of all updates |
| Reporting | ✅ Enabled | Users encouraged to flag issues |
Phase 1: Disable Adoptions Phase 2: Disable All Pushes
Technical Analysis of the Incident
The rate of malicious activity can be represented by the increase in compromised packages over time:
The attack vector generally follows this logic flow:
Community Action Plan
The DevOps team requests that all users remain vigilant. Please complete the following:
- Monitor your installed
AURpackages for unexpected changes. - Report any suspicious adoption events.
- Flag any commits that appear malicious and have not yet been reverted.
Verification & Metadata
For those verifying the authenticity of this communication, the following PGP signatures were attached to the original mailing list thread:
OpenPGP_0xFDC3040B92ACA748.asc (9.3 KB)
OpenPGP_signature.asc (840 bytes)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
AUR pushes and adoptions are currently suspended for security.
-----BEGIN PGP SIGNATURE-----
[Signature Data Redacted]
-----END PGP SIGNATURE-----

Regards,
Robin Candau / Antiz