More than 400 community packages for Arch Linux were modified to infect users with malware that steals passwords, tokens, and developer secrets. The attack hit the Arch User Repository (AUR), where a spoofed maintainer and hijacked orphaned packages were used to add install scripts that fetched a malicious npm package named atomic-lockfile. Researchers say the payload includes a Linux infostealer and optional eBPF rootkit features, with theft targets including GitHub, npm, SSH, HashiCorp Vault, Docker, browser cookies, and Slack, Discord, Teams, and Telegram data.
Why it matters: Arch users and developers who installed affected AUR packages may have exposed account credentials and system access, especially on developer workstations and build environments. Review the affected package list and indicators of compromise, remove malicious packages, rotate exposed secrets, and investigate for root-level persistence.
2026.06.15
95% relevant
This is a direct update on the same AUR compromise event, adding that the number of affected packages grew from about 400 to more than 1,500, that a more sophisticated second wave appeared on June 14, that the malicious packages tried to pull hostile npm JavaScript dependencies, and that Arch Linux disabled new AUR account registrations during cleanup.
info@thehackernews.com (The Hacker News)
2026.06.12
99% relevant
This article appears to report the same underlying event: hijacked Arch Linux AUR packages used to distribute an infostealer and an eBPF rootkit to users who installed the compromised packages.
info@thehackernews.com (The Hacker News)
2026.06.12
99% relevant
This is the same underlying event: a mass compromise of 400+ Arch Linux AUR packages to deliver malware. This source appears to add that the payload was described as a Rust-based credential stealer, but it does not establish a distinct incident.
Bill Toulas
2026.06.12
100% relevant
This article establishes a distinct software supply-chain incident centered on the Arch User Repository, with a defined infection chain, named malicious package, and broad package-compromise scope not covered by the existing tracked stories.
← Back to all stories