Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Malicious npm Campaign Steals SSH Keys & Cloud Credentials
June 12, 2026
Home/CyberSecurity News/Arch Linux AUR Supply Chain Attack Deploys Infostealers
CyberSecurity News

Arch Linux AUR Supply Chain Attack Deploys Infostealers

A massive supply chain attack has compromised over 400 community-maintained packages within the Arch User Repository (AUR). Attackers injected malicious build scripts into these packages, designed to...

Emy Elsamnoudy
Emy Elsamnoudy
June 12, 2026 3 Min Read
5 0

A massive supply chain attack has compromised over 400 community-maintained packages within the Arch User Repository (AUR). Attackers injected malicious build scripts into these packages, designed to deploy credential-stealing malware and rootkit-style payloads on affected Linux systems.

The campaign, dubbed “Atomic Arch” by researchers, was identified around June 11, 2026, and represents one of the most wide-scale AUR incidents on record.

The threat actors systematically targeted orphaned AUR packages legitimate projects that have been abandoned by their original maintainers and claimed ownership of them through AUR’s standard adoption process.

Once in control, attackers modified the packages’ PKGBUILD scripts, which are the build instruction files that AUR helpers like yay and paru execute during installation.

The malicious PKGBUILDs were altered to silently fetch and install two rogue npm packages: atomic-lockfile and js-digest. These packages acted as the primary malware delivery mechanism, executing during the standard package build process without triggering obvious warnings to end users.

AUR Packages Compromised With Infostealers

Once installed, the malicious npm packages deployed a multi-stage infostealer payload engineered to exfiltrate a broad range of sensitive data, including:

  • Browser credentials — saved passwords, session cookies, and autofill data from Chromium and Firefox-based browsers.
  • SSH private keys — enabling attackers to pivot to remote servers and infrastructure
  • System environment variables — potentially exposing API tokens, cloud credentials, and application secrets
  • Cryptocurrency wallet data — targeting local wallet files and seed phrases.

Beyond data theft, the malware employed rootkit-style persistence techniques, disguising its active processes as legitimate kernel threads to evade detection by standard process monitors like ps and htop. This tactic makes post-infection identification significantly harder without dedicated forensic tooling.

The Arch Linux security team responded rapidly once the compromise was surfaced on the AUR mailing list. Maintainers reverted malicious PKGBUILD commits, permanently banned the offending attacker accounts, and published a detailed checklist of affected packages for the community. Critically, Arch’s official repositories ([core], [extra], [multilib]) remained unaffected, as those are subject to stricter review processes.

Users who regularly install AUR packages should take the following steps immediately:

  1. Run pacman -Qm to list all foreign (AUR) packages installed on your system and cross-reference against the published list of compromised packages
  2. Audit recent PKGBUILD history for any packages installed between June 10–12, 2026
  3. Rotate all credentials — browser passwords, SSH keys, API tokens, and cloud access keys — if any flagged package was installed
  4. Scan for suspicious processes masquerading as kernel threads using tools like rkhunter or chkrootkit
  5. Consider using AUR helpers with PKGBUILD review prompts enabled by default.

This incident echoes a growing trend of supply chain attacks targeting package repositories across ecosystems. Researchers at Sonatype specifically characterized the Atomic Arch campaign as a deliberate strategy of targeting orphaned, trusted packages with existing install bases, maximizing victim reach while minimizing scrutiny.

The AUR’s community-trust model, while a strength for package availability, continues to present a systemic risk that individual vigilance cannot fully mitigate without structural policy changes around orphan package adoption.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical LangGraph Vulnerability Gives Attackers Full Server Control

Next Post

Google Sues Chinese Cybercrime for Gemini AI Cyberattacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Arch Linux AUR Supply Chain Attack Deploys Infostealers
June 12, 2026
Critical LangGraph Vulnerability Gives Attackers Full Server Control
June 12, 2026
SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us