More than 400 Arch Linux AUR packages were hijacked to install a Linux rootkit and credential-stealing malware

More than 400 community packages for Arch Linux were modified to infect users with malware that steals passwords, tokens, and developer secrets. The attack hit the Arch User Repository (AUR), where a spoofed maintainer and hijacked orphaned packages were used to add install scripts that fetched a malicious npm package named atomic-lockfile. Researchers say the payload includes a Linux infostealer and optional eBPF rootkit features, with theft targets including GitHub, npm, SSH, HashiCorp Vault, Docker, browser cookies, and Slack, Discord, Teams, and Telegram data.
Why it matters: Arch users and developers who installed affected AUR packages may have exposed account credentials and system access, especially on developer workstations and build environments. Review the affected package list and indicators of compromise, remove malicious packages, rotate exposed secrets, and investigate for root-level persistence.

Sources

Arch Linux locks down AUR signups amid wave of malicious commits
2026.06.15 95% relevant
This is a direct update on the same AUR compromise event, adding that the number of affected packages grew from about 400 to more than 1,500, that a more sophisticated second wave appeared on June 14, that the malicious packages tried to pull hostile npm JavaScript dependencies, and that Arch Linux disabled new AUR account registrations during cleanup.
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
info@thehackernews.com (The Hacker News) 2026.06.12 99% relevant
This article appears to report the same underlying event: hijacked Arch Linux AUR packages used to distribute an infostealer and an eBPF rootkit to users who installed the compromised packages.
400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
info@thehackernews.com (The Hacker News) 2026.06.12 99% relevant
This is the same underlying event: a mass compromise of 400+ Arch Linux AUR packages to deliver malware. This source appears to add that the payload was described as a Rust-based credential stealer, but it does not establish a distinct incident.
Over 400 Arch Linux packages compromised to push rootkit, infostealer
Bill Toulas 2026.06.12 100% relevant
This article establishes a distinct software supply-chain incident centered on the Arch User Repository, with a defined infection chain, named malicious package, and broad package-compromise scope not covered by the existing tracked stories.
← Back to all stories