The AUR nightmare is not ending for Arch Linux.
Arch User Repository (AUR) was the proud feature of Arch linux ecosystem.
Any software package out there was available in the community maintained AUR.
But then it became a point of supply chain attack.
Malicious users took control of abandoned AUR packages and started pushing malware.
The situation turned pandemic for Arch Linux and it is not ending at all, partially because AUR is built around community and you cannot always verify each and every single one of them.
A third wave is now underway, using a different delivery method: a Tor-based two-stage payload.
The attack starts at packages like openconnect-sso and has spread to 200+ packages, including recognizable names like i915-sriov-dkms, warp-terminal-git, boringssl-git, and rtk-git.
This round targets browser data, crypto wallets, SSH keys, API keys, and secrets. It also spreads via SSH to other machines on the same network.
On July 31, Arch Linux halted all AUR package adoptions entirely.
No new maintainer can take over an orphaned package right now while they work through the incident.
I see three solutions:
- Stick with official distro repositories
- Use straight from developers sources
- Compile from source code like it's the 90s
Add a 4th one?