The Arch Linux DevOps team has temporarily suspended pushes to the Arch User Repository (AUR) due to a recent influx of malicious package adoptions and commits, according to a message posted to the aur-general mailing list on August 1, 2026.

Robin Candau, writing on behalf of the Arch Linux DevOps team, announced that package adoption functionality was initially disabled on July 30, 2026, while the team investigated the situation. In a follow-up message, the team expanded the suspension to include all pushes to the AUR.
“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” Candau wrote in the initial message.
The subsequent message clarified the broader scope: “We have now disabled pushes altogether as well for the moment, while we handle the situation.”
The Arch Linux DevOps team did not provide specific details about the nature of the malicious activity or the number of affected packages. However, they encouraged users to report any suspicious adoption events or commits that have not yet been addressed.
“In the meantime, feel free to report suspicious adoption events or commits that haven’t been dealt with yet, and stay vigilant!” the team stated.
The AUR is a community-driven repository of user-submitted packages for Arch Linux. Package adoption occurs when a maintainer takes over stewardship of a package from a previous maintainer. The suspension affects the core functionality that allows contributors to submit new packages and update existing ones.
The team indicated that these restrictions are temporary and pledged to send a follow-up announcement once the situation is resolved. No timeline for the restoration of normal AUR operations was provided in the messages.
Key facts
- The Arch Linux DevOps team disabled AUR package adoption on July 30, 2026, and subsequently suspended all pushes to the repository
- The suspensions were triggered by a reported influx of malicious package adoptions and commits
- Users are encouraged to report suspicious adoption events and commits during the suspension
- The team has not provided specific details about the scope or nature of the malicious activity
