MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Arch Linux AUR malicious package campaign compromises software distribution

Attackers abused the Arch User Repository by taking control of orphaned packages and modifying legitimate PKGBUILD files so installations pulled a malicious dependency and rootkit. Arch Linux publicly acknowledged an active malicious-package campaign and temporarily restricted package adoption, creation and update functions while responding. The incident therefore compromised a legitimate software distribution channel rather than merely exposing data.

73

Estimated severity

73 / 100

—

Source reliability

No information

Approximate Date

11/06/2026

Targeted Company

ARCH LINUX

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impactService degradation

Affected sectors

Technology & IT Services

Affected departments

Engineering & MaintenanceInformation Technology

Attack Profile

Attack types

Software supply chain compromise

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.