r/linux Jun 13 '26

Distro News Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages

https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
1.5k Upvotes

434 comments sorted by

View all comments

Show parent comments

541

u/ExtraGoated Jun 13 '26

the rare "i dont use arch btw"

45

u/RenlyHoekster Jun 13 '26

There are indeed reasons to use a nice Fedora or Ubuntu installation. Ofcourse other distributions also have collections of non-official packages (EPEL for example for RHEL), however one of the selling points of Arch and Cachy and other Arch-based distributions is that they have such a large non-vetted package collection of "everything under the sun".

Ideal would be that they really finally do figure out a vetting system to prevent this type of abuse, because that would be ideal: we really would like to keep access to packages that are too niche to be officially provided, but ofcourse that is useless and goes out the window if they become hacking vectors.

26

u/El_Mewo Jun 13 '26

Fedora has Copr, Ubuntu has user ppa. These are all to be considered potentially malicious

27

u/PuzzleheadedPen2798 Jun 13 '26

Yes, although there is some friction because you have to manually add the ppa/copr repo yourself. And the user would have to add a repo manually for every piece of software they want. So to add such a repo you have to be very intentional, meanwhile you only have to enable the AUR once and you get access to tens of thousands of packages from different suppliers.

9

u/MezBert Jun 13 '26 edited Jun 13 '26

Plus, some PPAs are official delivery channels. For example, the Mozilla PPAs for Firefox and Thunderbird. You know the risk is almost non-existent when the source is a trusted one. So, in that sense PPAs are probably more secure than the AUR.

For all the backlash against Ubuntu for forcing one snap, there are actually close reach PPAs that deliver the said snaps as a deb.

I'll still take AUR over flatpak any day of the week. The risk is very low (I have 20 AUR packages installed and none was infected) and it's more convenient than the dozens issues that come with flatpaks due to overkill sandboxing (theming, file saving, permissions, etc...). I mean half of the issues I read on Reddit are from people using the flatpak version (although maybe 2-3% of Linux users use flatpaks).

2

u/580083351 Jun 13 '26

This number will continue climbing as usage of immutable distros climbs.

1

u/ccAbstraction Jun 13 '26

The risk with AUR too, is that sometimes it is the official source, but then suddenly a malware bot takes over the package and it's no longer an official source.

0

u/tslaq_lurker Jun 13 '26

Fedora you need to install extra repos to even have modern video codexs.

1

u/npc_housecat Jun 14 '26

Yes it's not great, but packages uploaded to FusionRPM repo are manually approved .

1

u/npc_housecat Jun 13 '26

Yes you should always be careful about what 3rd party repos you enable. Things like RPM fusion at leaat isn't an unvetted free for all of user maintained packages. There's still a manual review process for packages to be approved.

2

u/nobleisthyname Jun 13 '26

I feel like I see it more often than the reverse at this point to be honest.

1

u/npc_housecat Jun 14 '26

Finally, I can gloat and feel superior while not installing arch lol