AMAZINGINDEX.COM 日报快照
54.9
VOL. 2026.08
2026.08.01
← 返回 2026.08.01 日报
日报快照 · Daily Snapshot
NO. 016

Arch Linux 紧急关闭 AUR 包领养

#ARTICLE HackerNews 2026.08.01
推荐指数 39.0 NO. 016 · 2026.08.01
发布2026/07/31Score97Comments68

Arch Linux 因恶意用户批量领养废弃 AUR 包并植入 Tor 网络远控木马,已暂停包领养功能。此前 6 月已关闭新用户注册,攻击者正利用供应链信任链薄弱环节持续渗透。

这类攻击的精妙之处在于不碰官方仓库,只盯「孤儿包」——下载量不低但无人维护的灰色地带。攻击者批量注册账号、领养、推恶意更新,用户端的 pacman 签名验证完全不会报警。

如果你或团队有用 Arch/Manjaro 做开发机或 CI 镜像,建议立刻审计 AUR 包来源,优先换官方仓库替代,或锁定版本并手动校验 PKGBUILD。供应链安全的战场已经从 npm/PyPI 蔓延到系统级包管理器,防御策略需要同步升级。

意见分歧 63 条评论

核心争论:AUR包领养功能的安全风险是否可修复,还是必须彻底移除

delecti

That title had me worried, but the reality seems quite reasonable. I assumed the goal was to reduce usage of AUR, they've actually remove the ability to adopt (take ownership of) orphaned packages. I'm sure there are legitimate uses of that functionality, but it also seems like a pretty big avenue f

OJFord

I've used it (not for abuse). It's simply volunteering to maintain the package after previous maintainer(s) have explicitly disowned it, knowing they no longer have time for it or don't care because they stopped using it, etc.

gchamonlive

Problem is that there is no KYC process before someone can adopt any orphaned package

替代方案: DebianUbuntuWindowsMicrosoft GitHub
查看原文 →