VOOZH about

URL: https://www.phoronix.com/news/Arch-Linux-Malicious-AURs

⇱ Arch Linux AUR Packages For Firefox & Other Browsers Removed For Containing Malware - Phoronix


👁 Phoronix

Arch Linux AUR Packages For Firefox & Other Browsers Removed For Containing Malware

Written by Michael Larabel in Arch Linux on 19 July 2025 at 12:00 AM EDT. 94 Comments
While the Arch Linux AUR repository can be popular for fetching some packages not found in Arch Linux proper, it's important to keep in mind that AUR stands for the Arch User Repository. These user packages aren't always the best and rarely can be done with malicious intent as shown this week with an advisory over several malicious browser packages being briefly pedaled through AUR.

An Arch Linux user on Wednesday uploaded malicious AUR packages of firefox-patch-bin, librewolf-fix-bin, and zen-browser-patched-bin. These AUR packages ended up installing a binary file from a GitHub repository that ended up being a remote access trojan.

Arch Linux administrators were made aware of these malicious packages and as of Friday they were removed. It's important to reiterate that these malicious packages were just in the Arch User Repository (AUR) and were not part of the official Firefox browser on Arch Linux or similar. In any event a good public service announcement to remind users to exercise caution when relying on Arch Linux's AUR, Ubuntu PPAs, third-party Flatpaks / Snaps, and other user-contributed packages not always vetted by Linux distribution vendors.

More information on these compromised AUR packages via the Arch Linux aur-general mailing list.

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.