Attackers uploaded more than 1,500 malicious packages to Arch Linux’s user-run AUR repository, putting users at risk if they installed poisoned software. Arch Linux suspended new AUR account registrations while cleaning up the ongoing 'Atomic Arch' campaign. Researchers say attackers first modified abandoned packages, then added new ones, using altered PKGBUILD install scripts to fetch malicious npm and later Bun-based components that appear designed to steal credentials, SSH artifacts, Vault tokens, browser cookies, and to gain stealthy persistence through eBPF, a Linux kernel technology.
Why it matters: Arch Linux users who installed affected AUR packages should treat those systems as fully compromised, rebuild from clean media, and rotate credentials and secrets. This matters because AUR is widely used for unofficial software and the malware appears built for stealth, persistence, and secret theft rather than a one-off nuisance.
Ionut Arghire
2026.06.16
100% relevant
This article establishes a distinct large-scale AUR supply-chain compromise affecting Arch Linux packages, separate from the previously tracked story about 400 hijacked Arch Linux AUR packages.
← Back to all stories