Find notable cyber news and cases, enriched with sources, timelines, and signals.

Atomic-lockfile rootkit-infostealer distribution through AUR packages

Malware Activity
First reported
Last updated
Happening score
H score 3
2 unique sources, 2 articles

Summary

Hide ▲

AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the official Arch repositories not affected. The malicious path uses preinstall and post-install hooks to fetch [email protected], which runs a bundled Linux ELF named deps during builds. The payload targets developer secrets such as GitHub, SSH, Vault, Slack, Microsoft Teams, Discord, Docker/Podman, VPN, and browser and Electron data, and it can load an optional eBPF rootkit when built with root privileges.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

@Injectivelabs/[email protected] wallet-stealing package

Malware Activity
H score30 First: 10.07.2026 20:29 Last: 10.07.2026 20:29 Sources 1

About this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...

OpenMandriva Linux project hit by cyberattack

Incident
H score32 First: 10.07.2026 01:14 Last: 10.07.2026 01:14 Sources 1

About this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...

Timeline

  1. 12.06.2026 20:03 3 articles · 1mo ago

    AUR packages distribute atomic-lockfile rootkit and infostealer

    Initial Disclosure

    More than 400 packages in the Arch User Repository are distributing a Linux rootkit and infostealer through spoofed maintainer activity and malicious install scripts. The compromised packages download and execute atomic-lockfile, and one sample includes a Linux ELF payload named deps with optional root-only eBPF rootkit capabilities that can hide local processes while stealing developer credentials, access tokens, browser and Electron data, Slack, Microsoft Teams, Discord, GitHub, npm, Vault, Docker/Podman, SSH, VPN material, and shell histories.

    Show sources