Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Arch Linux AUR Packages Hijacked for Malware Deployment

Arch Linux AUR Packages Hijacked for Malware Deployment

Posted on June 12, 2026 By CWS

In a significant security breach, attackers have compromised more than 400 packages in the Arch User Repository (AUR), altering their build scripts to install a credential-stealing malware. This incident has raised alarms among users of Arch Linux, a popular distribution for developers and enthusiasts. The AUR, a community-driven repository, operates independently of the official Arch repositories, which remain unaffected.

How the Attack Unfolded

Beginning around June 11, the attackers rewrote build instructions in several AUR packages, inserting a malicious Rust binary designed to extract sensitive developer information. If the malware gains root access, it can deploy an eBPF rootkit to conceal its presence. The attack did not exploit any software vulnerabilities but rather targeted the trust inherent in the AUR’s open-source model.

The compromised packages retained their original names and histories, making it challenging for users to discern any malicious activity. The attackers exploited abandoned packages, modifying their build files and deceiving users into executing the harmful payload. Sonatype, an organization monitoring software supply chain threats, has termed this operation as ‘Atomic Arch.’

Impact and Exploitation

Notable packages affected include ‘alvr’ and ‘premake-git,’ with the malware capable of stealing a wide array of credentials. These include browser cookies, session data from applications like Slack and Discord, and various developer credentials. The malware communicates with a command-and-control server via a Tor onion service, ensuring its persistence by installing a systemd service.

The eBPF rootkit, although optional, can hide the malware’s activities if activated. It employs BPF maps to obscure processes and file activities from standard monitoring tools. Analysts emphasize that simply removing the AUR package does not eliminate the threat if the malicious payload has already executed.

Community Response and Recommendations

The Arch Linux community, alongside Sonatype, has been actively documenting and mitigating the impact of this attack. Users are advised to verify any AUR packages installed or updated post-June 11 against known malicious lists. It is crucial to rotate all potentially compromised credentials and inspect systems for any unauthorized services or connections.

As the attack continues to unfold, Arch maintainers are reverting malicious commits and blocking the involved accounts. Users are encouraged to scrutinize package build scripts carefully, especially for recently adopted or unexpectedly active packages. The ongoing threat underlines the need for vigilance within open-source ecosystems.

This breach highlights a fundamental vulnerability in software supply chains where trust is placed in package names and histories, rather than current maintainers. As the community works to address these concerns, it remains vital for users to adopt proactive security measures.

The Hacker News Tags:Arch Linux, AUR, credential theft, Cybersecurity, developer security, eBPF rootkit, Hijacking, InfoStealer, Linux, Malware, Open Source, package management, Rootkit, Software Security, supply chain attack

Post navigation

Previous Post: Fancy Bear Exploits Routers and Cloud for Covert Cyberattacks
Next Post: Google Security Layoffs and Major Cybersecurity Incidents

Related Posts

Anthropic Introduces Claude Code Security for AI Vulnerability Scanning Anthropic Introduces Claude Code Security for AI Vulnerability Scanning The Hacker News
Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations The Hacker News
Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows The Hacker News
China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services The Hacker News
Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files The Hacker News
Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm
  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm
  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark