Atomic-lockfile rootkit-infostealer distribution through AUR packages
Malware Activity
Summary
Hide ▲
Show ▼
AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the official Arch repositories not affected. The malicious path uses preinstall and post-install hooks to fetch [email protected], which runs a bundled Linux ELF named deps during builds. The payload targets developer secrets such as GitHub, SSH, Vault, Slack, Microsoft Teams, Discord, Docker/Podman, VPN, and browser and Electron data, and it can load an optional eBPF rootkit when built with root privileges.
Related Happenings
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
@Injectivelabs/[email protected] wallet-stealing package
Malware Activity
H score30
First: 10.07.2026 20:29
Last: 10.07.2026 20:29
Sources 1
About this happening:
The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
@Injectivelabs/[email protected] wallet-stealing package
Malware ActivityAbout this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
OpenMandriva Linux project hit by cyberattack
Incident
H score32
First: 10.07.2026 01:14
Last: 10.07.2026 01:14
Sources 1
About this happening:
The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
OpenMandriva Linux project hit by cyberattack
IncidentAbout this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
Timeline
-
12.06.2026 20:03 3 articles · 1mo ago
AUR packages distribute atomic-lockfile rootkit and infostealer
Initial DisclosureMore than 400 packages in the Arch User Repository are distributing a Linux rootkit and infostealer through spoofed maintainer activity and malicious install scripts. The compromised packages download and execute atomic-lockfile, and one sample includes a Linux ELF payload named deps with optional root-only eBPF rootkit capabilities that can hide local processes while stealing developer credentials, access tokens, browser and Electron data, Slack, Microsoft Teams, Discord, GitHub, npm, Vault, Docker/Podman, SSH, VPN material, and shell histories.
Show sources
- Over 400 Arch Linux packages compromised to push rootkit, infostealer — www.bleepingcomputer.com — 12.06.2026 20:03
- Over 400 Arch Linux packages compromised to push rootkit, infostealer — www.bleepingcomputer.com — 12.06.2026 20:03
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit — thehackernews.com — 12.06.2026 22:33