Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware
Over 400 user-contributed packages on the Arch Linux User Repository have been compromised in a widespread supply chain attack.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A campaign has targeted the Arch Linux User Repository (AUR), resulting in the compromise of more than 400 packages. The malicious activity involves the deployment of infostealers, a Rust-based credential stealer, and an eBPF rootkit via hijacked package descriptions and dependencies.
Coverage from outlets including Phoronix, The Hacker News, and Sonatype emphasizes that the campaign utilizes an "Atomic Arch" methodology to distribute malicious code. Reports from heise online, GamingOnLinux, and Linuxiac highlight that the threat specifically affects user-contributed content within the repository.
Future developments will focus on the remediation of affected packages and potential security updates for the AUR ecosystem. Details regarding the identities of the attackers or the full extent of impacted user systems are currently unspecified.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 50d ago.
Quick answers
How many packages were affected?
Coverage indicates that more than 400 packages within the Arch Linux User Repository were compromised.
What types of malware are involved?
Reported threats include infostealers, a Rust credential stealer, and an eBPF rootkit.
What is the name of this campaign?
The campaign has been referred to by sources such as Security Boulevard and Sonatype as "Atomic Arch."
Coverage (9)
- Attack wave on Arch Linux: hundreds of package descriptions with malware in AUR heise online · 51d ago
- 400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer The Hacker News · 51d ago
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit The Hacker News · 51d ago
- 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers CyberSecurityNews · 51d ago
- The Arch Linux AUR had over 400 packages compromised with malware GamingOnLinux · 51d ago
- Atomic Arch npm Campaign Adds Malicious Dependency Security Boulevard · 51d ago
- Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages Linuxiac · 51d ago
- Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware Sonatype · 51d ago
- Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware Phoronix · 51d ago
Topics
Related trends
Anthropic, OpenAI Cyber Failures Point to US Security Risks
2 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
OpenAI reportedly finds evidence that more of its agents ran amok
2 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google Chrome has released a series of updates fixing 1,442 flaws, a volume exceeding the previous 23 updates combined.
JetBrains warns of critical TeamCity remote code execution flaw
6 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
KARR Bluetooth flaw exposes 2.2M cars to theft risk
5 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Beware: attackers now using real Microsoft sign-in screen for phishing
7 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.