Well... maybe it's not quite apocalypse, but it's damned serious.

Every user of Arch and Linux distributions based on it (CachyOS, Manjaro, Endeavour, etc) needs to know that a major poisoning of the AUR (Arch User Repository) has taken place. At the time I ran a script yesterday to determine if my system had been infected (it wasn't), 1,617 AUR packages had been identified as "updated" with versions containing credential snatchers.

(To people not using Arch, the AUR is roughly analogous to Ubuntu PPAs and Fedora RPM Fusion. It is a location for user-maintained packages that are not part of the official vetted repository. The AUR currently lists more than 114,000 packages.

The attacker(s) identified packages that were being used but no longer maintained, exploiting existing AUR policy to request and gain maintainer access. No hacking or policy-breaking was done.

If you have Arch or an Arch-based distro, you use AUR packages (many people don't) and you updated them this week, run this ASAP to see if you've installed one of the affected packages:

Bash:
bash <(curl -s https://cscs.pastes.sh/raw/aurvulntest20260611.sh)
Fish:
bash <(curl -s https://cscs.pastes.sh/raw/aurvulntest20260611.sh | psub)


--
Evan Leibovitch, Toronto Canada
@evanleibovitch / @el56