PULSE the living trend engine
◼ Archived Technology 🔮 PULSE predicts: fades by tomorrow

Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware

Over 400 user-contributed packages on the Arch Linux User Repository have been compromised in a widespread supply chain attack.

8sources
9articles
6velocity
+0%since first seen
51d agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

A campaign has targeted the Arch Linux User Repository (AUR), resulting in the compromise of more than 400 packages. The malicious activity involves the deployment of infostealers, a Rust-based credential stealer, and an eBPF rootkit via hijacked package descriptions and dependencies.

Coverage from outlets including Phoronix, The Hacker News, and Sonatype emphasizes that the campaign utilizes an "Atomic Arch" methodology to distribute malicious code. Reports from heise online, GamingOnLinux, and Linuxiac highlight that the threat specifically affects user-contributed content within the repository.

Future developments will focus on the remediation of affected packages and potential security updates for the AUR ecosystem. Details regarding the identities of the attackers or the full extent of impacted user systems are currently unspecified.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 50d ago.

Quick answers

How many packages were affected?

Coverage indicates that more than 400 packages within the Arch Linux User Repository were compromised.

What types of malware are involved?

Reported threats include infostealers, a Rust credential stealer, and an eBPF rootkit.

What is the name of this campaign?

The campaign has been referred to by sources such as Security Boulevard and Sonatype as "Atomic Arch."

Coverage (9)

Topics

Related trends