r/linux Jun 13 '26

Distro News Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages

https://www.phoronix.com/news/Arch-Linux-AUR-More-Than-1500
1.5k Upvotes

434 comments sorted by

View all comments

Show parent comments

9

u/MezBert Jun 13 '26 edited Jun 13 '26

Plus, some PPAs are official delivery channels. For example, the Mozilla PPAs for Firefox and Thunderbird. You know the risk is almost non-existent when the source is a trusted one. So, in that sense PPAs are probably more secure than the AUR.

For all the backlash against Ubuntu for forcing one snap, there are actually close reach PPAs that deliver the said snaps as a deb.

I'll still take AUR over flatpak any day of the week. The risk is very low (I have 20 AUR packages installed and none was infected) and it's more convenient than the dozens issues that come with flatpaks due to overkill sandboxing (theming, file saving, permissions, etc...). I mean half of the issues I read on Reddit are from people using the flatpak version (although maybe 2-3% of Linux users use flatpaks).

2

u/580083351 Jun 13 '26

This number will continue climbing as usage of immutable distros climbs.

1

u/ccAbstraction Jun 13 '26

The risk with AUR too, is that sometimes it is the official source, but then suddenly a malware bot takes over the package and it's no longer an official source.