Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Arch Linux AUR Packages Hijacked for Malware Deployment

Arch Linux AUR Packages Hijacked for Malware Deployment

Posted on June 12, 2026 By CWS

In a significant security breach, attackers have compromised more than 400 packages in the Arch User Repository (AUR), altering their build scripts to install a credential-stealing malware. This incident has raised alarms among users of Arch Linux, a popular distribution for developers and enthusiasts. The AUR, a community-driven repository, operates independently of the official Arch repositories, which remain unaffected.

How the Attack Unfolded

Beginning around June 11, the attackers rewrote build instructions in several AUR packages, inserting a malicious Rust binary designed to extract sensitive developer information. If the malware gains root access, it can deploy an eBPF rootkit to conceal its presence. The attack did not exploit any software vulnerabilities but rather targeted the trust inherent in the AUR’s open-source model.

The compromised packages retained their original names and histories, making it challenging for users to discern any malicious activity. The attackers exploited abandoned packages, modifying their build files and deceiving users into executing the harmful payload. Sonatype, an organization monitoring software supply chain threats, has termed this operation as ‘Atomic Arch.’

Impact and Exploitation

Notable packages affected include ‘alvr’ and ‘premake-git,’ with the malware capable of stealing a wide array of credentials. These include browser cookies, session data from applications like Slack and Discord, and various developer credentials. The malware communicates with a command-and-control server via a Tor onion service, ensuring its persistence by installing a systemd service.

The eBPF rootkit, although optional, can hide the malware’s activities if activated. It employs BPF maps to obscure processes and file activities from standard monitoring tools. Analysts emphasize that simply removing the AUR package does not eliminate the threat if the malicious payload has already executed.

Community Response and Recommendations

The Arch Linux community, alongside Sonatype, has been actively documenting and mitigating the impact of this attack. Users are advised to verify any AUR packages installed or updated post-June 11 against known malicious lists. It is crucial to rotate all potentially compromised credentials and inspect systems for any unauthorized services or connections.

As the attack continues to unfold, Arch maintainers are reverting malicious commits and blocking the involved accounts. Users are encouraged to scrutinize package build scripts carefully, especially for recently adopted or unexpectedly active packages. The ongoing threat underlines the need for vigilance within open-source ecosystems.

This breach highlights a fundamental vulnerability in software supply chains where trust is placed in package names and histories, rather than current maintainers. As the community works to address these concerns, it remains vital for users to adopt proactive security measures.

The Hacker News Tags:Arch Linux, AUR, credential theft, Cybersecurity, developer security, eBPF rootkit, Hijacking, InfoStealer, Linux, Malware, Open Source, package management, Rootkit, Software Security, supply chain attack

Post navigation

Previous Post: Fancy Bear Exploits Routers and Cloud for Covert Cyberattacks
Next Post: Google Security Layoffs and Major Cybersecurity Incidents

Related Posts

Google Addresses Critical Chrome Zero-Day Vulnerability Google Addresses Critical Chrome Zero-Day Vulnerability The Hacker News
Tropic Trooper Utilizes Trojanized Software for Cyber Attacks Tropic Trooper Utilizes Trojanized Software for Cyber Attacks The Hacker News
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs The Hacker News
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide The Hacker News
CTEM’s Core: Prioritization and Validation CTEM’s Core: Prioritization and Validation The Hacker News
Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Gentlemen Ransomware Hits 478, Spreads Like a Worm
  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls
  • U.S. Halts Foreign Access to Anthropic’s AI Models
  • SHEETCREEP RAT Exploits Google Sheets for Covert Ops

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Gentlemen Ransomware Hits 478, Spreads Like a Worm
  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls
  • U.S. Halts Foreign Access to Anthropic’s AI Models
  • SHEETCREEP RAT Exploits Google Sheets for Covert Ops

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark