Arch Linux locks down AUR signups amid wave of malicious commits
Community repo freezes new accounts after attackers swamp it with poisoned package updates
A wave of malicious commits hit the Arch User Repository (AUR) over the weekend, prompting the team to disable new account registration on Monday morning while it cleans up the mess.
The issue was first acknowledged on June 12, with a post stating: "We are currently experiencing a high volume of malicious package adoptions and updates in the Arch User Repository."
The team warned that users might have issues opening new accounts, pushing package updates, and adopting or creating fresh packages.
Around 400 user-submitted packages were believed compromised; that figure climbed past 1,500 over the weekend. On June 14, a more sophisticated wave of malicious packages was spotted. The Arch Linux team this morning disabled new account registration "while we are working on the cleanup."
The core Arch distribution itself is unaffected. The AUR is a...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE