Amid a malware surge that compromised over 1,500 Arch Linux AUR packages, attackers started injecting Russian spam and offensive messages into AUR commits and post-install configuration, now affecting more than 70 packages across Python, Ruby, Llama.cpp and others, with AI/LLM bots helping to flag abuse.
A day after Arch Linux AUR’s initial malware incident, a second wave of more sophisticated, obfuscated malware hit user-supplied packages (including Node.js, Plasma 6 applets, Firefox, Aura browser, LibreWolf extensions, and a NeoVim plug‑in). Reported by a821 and later by Nicolas Boichat, the affected packages were addressed, but experts warn that AUR security safeguards may need strengthening or a temporary shutdown until verification improves.
Over 400 Arch User Repository packages were compromised after a spoofed maintainer injected malicious post-install steps that install a rogue npm package (atomic-lockfile) containing a Linux ELF with an eBPF rootkit and credential-stealing capabilities. The malware targets developer data and tokens across tools like Slack, Teams, Discord, GitHub, Vault, and SSH, and can exfiltrate data via HTTP. Researchers from IFIN and Sonatype describe two attack methods: hijacking orphaned PKGBUILD files to run npm post-install, and abusing a trusted maintainer identity to push malicious commits. Arch is removing the malicious commits and banning accounts; affected users should review indicators of compromise, rotate credentials, and consider reinstalling Arch if compromised.
A supply-chain attack hijacked more than 400 Arch Linux AUR packages by modifying their build scripts to install a Rust-based credential stealer that can also load an eBPF rootkit when run with root; the attackers targeted abandoned packages to exploit trust, persisted via systemd, and used Tor for C2, prompting users to audit builds, rotate credentials, and thoroughly clean systems rather than assuming safety from package managers.
A large-scale malware campaign targeted Arch Linux's AUR, compromising over 400 user-submitted packages. Arch maintainers are actively resetting and deleting the malicious content and banning affected accounts; officials say the impact is limited to AUR and does not affect Arch's official packages, with discussions on mailing lists and CachyOS forums detailing the incidents.
Romania’s Social Democrats teamed up with the far-right AUR to topple the government, forcing Brussels’ center-left to defend its credibility and navigate conflicting red lines as mainstream parties broaden cooperation with the far right.
As Romania’s governing coalition buckles over austerity and spending cuts, MAGA-aligned George Simion and his Alliance for the Union of Romanians lead in national polls and push for a shot at governing, threatening Brussels’ priorities while parties negotiate a way forward amid looming no-confidence motions and potential elections, with EU funds and defense contracts at stake.
Zayn Malik collaborates with Pakistani group Aur on a reimagining of their hit single "Tu Hai Kahan," joining the trio on vocals in Hindi. The music video for the song features Malik in his home studio. The collaboration aims to take Pakistani music global, with the original song having reached No. 1 on South Asian charts. Malik also discussed his return to music and upcoming projects, including a new record with a different sound and more narrative elements.