Country visual unavailable
No information
Attackers abused the Arch User Repository by taking control of orphaned packages and modifying legitimate PKGBUILD files so installations pulled a malicious dependency and rootkit. Arch Linux publicly acknowledged an active malicious-package campaign and temporarily restricted package adoption, creation and update functions while responding. The incident therefore compromised a legitimate software distribution channel rather than merely exposing data.
Estimated severity
73 / 100
Source reliability
No information
Approximate Date
11/06/2026
Targeted Company
ARCH LINUX
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone