Find notable cyber news and cases, enriched with sources, timelines, and signals.

Arch Linux AUR malicious package takeover campaign

Campaign
First reported
Last updated
Happening score
H score 47
1 unique sources, 1 articles

Summary

Hide ▲

A malicious package takeover campaign in the Arch User Repository (AUR) is exposing users to stealer malware and forcing temporary package-adoption disablement. Researchers say the operation began on July 29 with openconnect-sso and appears similar to an earlier AUR abuse wave. The delivery chain uses follow-up commits, Tor-based staging, and a two-stage infection that installs persistence before downloading the payload from an .onion server. Reported expansion to over 200 AUR packages raises the risk of wider credential theft, wallet theft, and lateral spread through stolen SSH keys.

Related Happenings

Arch Linux AUR two-stage infostealer malware activity

Malware Activity
H score34 First: 01.08.2026 00:38 Last: 01.08.2026 00:38 Sources 1

How related: "In the latest attack, the researchers identified a two-stage infection, with the first stage acting as the loader, and the second one being a Linux x86_64 payload described as stealer malware with remote administration (RAT) and SSH worm features."

About this happening: AUR-delivered Linux malware is now using a two-stage infection chain that installs persistence and fetches a Tor-routed payload, increasing the risk of credential theft,...

Arch Linux AUR package adoption temporary disruption

Service Disruption
H score38 First: 01.08.2026 00:38 Last: 01.08.2026 00:38 Sources 1

How related: “Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.

About this happening: The Arch User Repository (AUR) temporarily disabled package adoption, disrupting maintenance workflows while malicious takeovers were handled. The pause affects a core rep...

Deps credential stealer in hijacked Arch AUR builds

Malware Activity
H score3 First: 12.06.2026 22:24 Last: 12.06.2026 22:24 Sources 1

About this happening: Atomic Arch is a malware activity that hijacked more than 400 Arch User Repository (AUR) packages on or after June 11 and rewrote their build scripts to run npm...

Atomic-lockfile rootkit-infostealer distribution through AUR packages

Malware Activity
H score3 First: 12.06.2026 20:03 Last: 12.06.2026 20:03 Sources 1

About this happening: AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...

AUR package-hijacking campaign delivering atomic-lockfile

Campaign
H score11 First: 12.06.2026 20:03 Last: 12.06.2026 20:03 Sources 1

About this happening: AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...

Timeline

  1. 01.08.2026 00:38 1 articles · 1h ago

    Malicious AUR campaign begins with openconnect-sso

    Technical Analysis Update

    A malicious Arch User Repository (AUR) campaign targeting Arch Linux users began on July 29 with openconnect-sso, and IFIN identified a two-stage infection that used Tor-based staging. The first-stage loader checked for debuggers, sandboxes, virtual machines, and CI/CD environments before installing systemd services and cron jobs for persistence, then launched a Tor client disguised as dbus-daemon to retrieve a second-stage Rust-based infostealer with remote administration (RAT) and SSH worm features.

    Show sources
  2. 01.08.2026 00:38 2 articles · 1h ago

    Arch Linux disables AUR package adoption amid malicious takeovers

    Mitigation Patch Update

    Arch Linux temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious package takeovers, saying adoption would remain disabled while the situation is handled and asking maintainers to report suspicious adoption events or commits. The same reporting said a Reddit user tracking the campaign alleged expansion to over 200 AUR packages through compromised maintainer accounts or orphaned-package adoption, naming boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server, though that wider compromise list was not independently confirmed.

    Show sources