Arch Linux AUR malicious package takeover campaign
Campaign
Summary
Hide ▲
Show ▼
A malicious package takeover campaign in the Arch User Repository (AUR) is exposing users to stealer malware and forcing temporary package-adoption disablement. Researchers say the operation began on July 29 with openconnect-sso and appears similar to an earlier AUR abuse wave. The delivery chain uses follow-up commits, Tor-based staging, and a two-stage infection that installs persistence before downloading the payload from an .onion server. Reported expansion to over 200 AUR packages raises the risk of wider credential theft, wallet theft, and lateral spread through stolen SSH keys.
Related Happenings
Arch Linux AUR two-stage infostealer malware activity
Malware Activity
H score34
First: 01.08.2026 00:38
Last: 01.08.2026 00:38
Sources 1
How related:
"In the latest attack, the researchers identified a two-stage infection, with the first stage acting as the loader, and the second one being a Linux x86_64 payload described as stealer malware with remote administration (RAT) and SSH worm features."
About this happening:
AUR-delivered Linux malware is now using a two-stage infection chain that installs persistence and fetches a Tor-routed payload, increasing the risk of credential theft,...
Arch Linux AUR two-stage infostealer malware activity
Malware ActivityHow related: "In the latest attack, the researchers identified a two-stage infection, with the first stage acting as the loader, and the second one being a Linux x86_64 payload described as stealer malware with remote administration (RAT) and SSH worm features."
About this happening: AUR-delivered Linux malware is now using a two-stage infection chain that installs persistence and fetches a Tor-routed payload, increasing the risk of credential theft,...
Arch Linux AUR package adoption temporary disruption
Service Disruption
H score38
First: 01.08.2026 00:38
Last: 01.08.2026 00:38
Sources 1
How related:
“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.
About this happening:
The Arch User Repository (AUR) temporarily disabled package adoption, disrupting maintenance workflows while malicious takeovers were handled. The pause affects a core rep...
Arch Linux AUR package adoption temporary disruption
Service DisruptionHow related: “Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.
About this happening: The Arch User Repository (AUR) temporarily disabled package adoption, disrupting maintenance workflows while malicious takeovers were handled. The pause affects a core rep...
Deps credential stealer in hijacked Arch AUR builds
Malware Activity
H score3
First: 12.06.2026 22:24
Last: 12.06.2026 22:24
Sources 1
About this happening:
Atomic Arch is a malware activity that hijacked more than 400 Arch User Repository (AUR) packages on or after June 11 and rewrote their build scripts to run npm...
Deps credential stealer in hijacked Arch AUR builds
Malware ActivityAbout this happening: Atomic Arch is a malware activity that hijacked more than 400 Arch User Repository (AUR) packages on or after June 11 and rewrote their build scripts to run npm...
Atomic-lockfile rootkit-infostealer distribution through AUR packages
Malware Activity
H score3
First: 12.06.2026 20:03
Last: 12.06.2026 20:03
Sources 1
About this happening:
AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...
Atomic-lockfile rootkit-infostealer distribution through AUR packages
Malware ActivityAbout this happening: AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...
AUR package-hijacking campaign delivering atomic-lockfile
Campaign
H score11
First: 12.06.2026 20:03
Last: 12.06.2026 20:03
Sources 1
About this happening:
AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...
AUR package-hijacking campaign delivering atomic-lockfile
CampaignAbout this happening: AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...
Timeline
-
01.08.2026 00:38 1 articles · 1h ago
Malicious AUR campaign begins with openconnect-sso
Technical Analysis UpdateA malicious Arch User Repository (AUR) campaign targeting Arch Linux users began on July 29 with openconnect-sso, and IFIN identified a two-stage infection that used Tor-based staging. The first-stage loader checked for debuggers, sandboxes, virtual machines, and CI/CD environments before installing systemd services and cron jobs for persistence, then launched a Tor client disguised as dbus-daemon to retrieve a second-stage Rust-based infostealer with remote administration (RAT) and SSH worm features.
Show sources
- Arch Linux disables AUR package adoption to stop malware flood — www.bleepingcomputer.com — 01.08.2026 00:38
-
01.08.2026 00:38 2 articles · 1h ago
Arch Linux disables AUR package adoption amid malicious takeovers
Mitigation Patch UpdateArch Linux temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious package takeovers, saying adoption would remain disabled while the situation is handled and asking maintainers to report suspicious adoption events or commits. The same reporting said a Reddit user tracking the campaign alleged expansion to over 200 AUR packages through compromised maintainer accounts or orphaned-package adoption, naming boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server, though that wider compromise list was not independently confirmed.
Show sources
- Arch Linux disables AUR package adoption to stop malware flood — www.bleepingcomputer.com — 01.08.2026 00:38
- Arch Linux disables AUR package adoption to stop malware flood — www.bleepingcomputer.com — 01.08.2026 00:38