← 返回日报
略读 预计 1 分钟

Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages

摘要

Arch Linux 的用户贡献软件库(AUR)近日爆发严重安全事件,受影响包数量从最初发现的 400 个激增至 1579 个。目前开发者已删除所有已知的恶意提交并表示事态已受控,但官方名单提示仍可能存在未被发现的受影响软件包。

荐读理由

若使用 Arch Linux 构建 AI 工程环境,需根据此次 AUR 仓库 1,579 个包受污染的事故,排查开发机是否存在供应链安全隐患。

原文

Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages

Written by Michael Larabel in Arch Linux on 12 June 2026 at 08:55 PM EDT. 41 Comments

ARCH LINUX

The day started out with Arch Linux's AUR user-contributed repository seeing more than 400 packages compromised with malware. Now in ending out the day they believe all affected commits have been addressed. But it ended up being more than 1,500 affected packages.

It was bad enough when finding out more than 400 AUR packages for Arch Linux users had been infected with malware but now that number has risen to around 900 a few hours ago and now in the end at more than 1,500 user-contributed packages.

In an update a few hours ago, it was believed around 900 packages were infected by malware in this week's incident.

Then as of writing now, the last message in the thread over this security incident is noting that Arch Linux developers have deleted all the malicious commits they are aware of. Cited was this list that puts the number of malware-affected packages at 1,579! Tons of software in this user-maintained Arch Linux user repository were impacted by this nasty security incident.

Even at 1,579 packages listed, that final updated noted, it's a "list containing many (but not all) of the affected packages". Ouch.

Hacker News · 156 赞 · 67 评 讨论 → 阅读原文 →

这条对你有帮助吗?