Arch Linux is
dealing with one of the largest security incidents to hit the Arch User Repository in recent memory, as maintainers continue cleaning up a wave of malicious package updates across the community-maintained platform.
Importantly, the AUR remains online, and packages are accessible. However, new account registration is unavailable, with the
registration page returning a 503 Service Unavailable error. While not officially announced, this suggests Arch has temporarily blocked an entry point as it works through the cleanup.
The move follows
an official Arch Linux warning notice dated June 12 about a “high volume” of malicious package adoptions and updates in the AUR. Maintainers are tracking down malicious commits and trying to prevent more from being pushed while preparing a permanent solution.
Arch also warned users may experience problems with new account creation, package updates, adoptions, and new package creation during the response.
Unfortunately, the incident appears far larger than early reports suggested. Initial public reports pointed to over 400 affected AUR packages, while later community tracking raised the number to more than 1,500. The final count may still change as maintainers continue auditing and removing malicious changes.