[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-malware-spreads-through-1500-arch-user-repository-packages":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},1468,"malware-spreads-through-1500-arch-user-repository-packages","1,500 Arch Linux AUR Packages Hijacked in Credential-Theft Attack","Over 1,500 Arch Linux community packages were seeded with credential-stealing malware last weekend, and no vulnerability was required to do it.","More than 1,500 packages in the Arch User Repository were secretly replaced with credential-stealing malware last weekend, and the attackers never had to break a single lock.\n\nThe Arch User Repository, known as AUR, is a community-maintained software collection that supplements Arch Linux's official repos. Unlike the official repositories, AUR packages are submitted and maintained by volunteer contributors with minimal central oversight. Attackers exploited that open trust model to seize control of more than 1,500 packages, injecting code designed to harvest developer secrets and credentials. Arch Linux maintainers spent the weekend identifying and cleaning out the affected packages.\n\nAUR has always carried a warning label: it is community-run, largely unvetted, and users are expected to review build scripts before installing anything. In practice, few developers audit every PKGBUILD they run. At 1,500 compromised packages, the attack was large enough to catch developers who had done nothing obviously wrong - just installed software from a source they had trusted for years.\n\nSupply chain attacks that exploit open-contribution systems rather than finding bugs in them are not new - the same playbook has burned npm and PyPI users repeatedly. The only surprise is that it took this long to land on AUR at this scale.","[\"supply chain\",\"arch linux\",\"malware\",\"open source\"]","2026-06-16T15:16:34.000Z","2026-06-17T13:24:31.464Z","2026-06-19T13:17:17.779Z","published",null,[],"security",[26,27,28,29],"supply chain","arch linux","malware","open source",[31],{"name":32,"url":33},"The Next Web","https:\u002F\u002Fthenextweb.com\u002Fnews\u002Farch-linux-aur-malware-credential-stealer-supply-chain",0,{"sections":36},[37,42,46,51,56,61,66,71,76,81,86,91,96,101],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",2602,"2026-07-18T18:30:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",315,"2026-07-17T19:30:00.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",169,"2026-07-17T19:49:53.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",126,"2026-07-16T20:09:48.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Consumer Tech","consumer-tech",94,"2026-07-16T16:29:46.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Software","software",72,"2026-07-17T09:42:05.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Science","science",66,"2026-07-10T10:29:37.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Dev Tools","dev-tools",60,"2026-07-16T16:59:13.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Startups","startups",42,"2026-07-16T16:30:35.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"General","general",29,"2026-07-10T22:28:58.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]