By Larry Cafiero
Senthilkumar Palani (aka SK) wrote in OS Technix on Thursday a guideline regarding how to safely use the Arch User Repository (AUR), which was compromised to the tune of over 1,500 programs recently.
![]()
According to the article – and to recap – back in June, “a attackers compromised more than 1,500 packages in the Arch User Repository (AUR). Sonatype researchers named the campaign Atomic Arch. It is one of the largest attacks against the AUR to date.”
The article continues to say that the attack did not exploit a flaw in Arch Linux or its package manager, Pacman. The official Arch repositories were not affected.
The article details a wide range of steps Arch users may want to take to avoid pitfalls in the future, which is worth a read, especially if you’re an Arch user.
In summary, the article states that the malware campaign is not a reason to stop using Arch or the AUR, but “[i]t is a reminder that trust should be earned and reviewed over time.”
“The attack did not exploit a vulnerability in Arch Linux,” the article explains. “It exploited the trust users placed in packages that changed maintainers. The same idea appears in many software supply chain attacks. Attackers often target trusted software instead of technical vulnerabilities.”
Gnome makes testing safer
Sourav Rudra at It’s FOSS wrote on Thursday about a unique situation that Gnome has provided its users regarding testing software before actually using it.
Tentatively callled Test Center, “It is meant to act as a one-stop solution for installing, running, and removing anything experimental, whether that’s an app or a piece of the system itself.”

The article continues to explain that system components “run on sysext images instead of Flatpaks, though the idea plays out the same way. Take something like parental controls, still early in development, you’d grab the sysext tied to that merge request through Test Center, and it lands on your system as an overlay rather than a replacement. Remove it, and you restore your system to the same state before the experimental change was applied.”
Neat.
“All this effort is part of the Gnome OS Developer Tool Suite, a project that’s been in funding through Germany’s Prototype Fund since June 2026,” the article continues. “Tobias Bernard, Jonas Dreßler, and a few others are working on this under the Modal Collective umbrella.”
Void Linux gets new package manager
World, welcome to Caerus.
Bobby Borisov of Linuxiac reported on Wednesday that Void Linux is getting another Synaptic-like GTK4 package manager in the form of a new program called Caerus.

“Void Linux users looking for a GUI alternative to command-line package management now have yet another option,” the article states. “Called Caerus, the application is a GTK4 front end for the distribution’s XBPS package system, inspired by the well-known Synaptic Package Manager.”
Written mainly in Rust, Caerus exposes both routine and advanced XBPS operations through a desktop interface. Users can search the package collection, sort and filter results, and mark multiple packages for installation, upgrading, removal, or other actions.
“The available filters include installed, not installed, upgradable, held, marked, and orphaned packages,” the article continues. “Selecting a package opens a detailed information pane containing its description, size, maintainer, tags, dependencies, reverse dependencies, conflicts, replacements, shared-library requirements, and an optional list of installed files.”
The article also states that Caerus “is an independent community project rather than an official Void Linux app. The repository also states that the software was developed with substantial assistance from Anthropic’s Claude and directs users to a separate disclaimer covering its development process, security assumptions, and known risks.”
And that’s all for today. Don’t forget: Distro of the Week appears Wednesday – and it’s always a good one on hand – and Bits and Bobs will return on Monday.