Arch Linux AUR two-stage infostealer malware activity
Malware Activity
Summary
Hide ▲
Show ▼
AUR-delivered Linux malware is now using a two-stage infection chain that installs persistence and fetches a Tor-routed payload, increasing the risk of credential theft, wallet theft, and lateral spread on affected systems. The second-stage payload is a Rust-based infostealer with RAT and SSH worm features. The activity has been tied to malicious package adoptions in the Arch User Repository and broader package spread.
Related Happenings
Arch Linux AUR malicious package takeover campaign
Campaign
H score47
First: 01.08.2026 00:38
Last: 01.08.2026 00:38
Sources 1
How related:
“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.
About this happening:
A malicious package takeover campaign in the Arch User Repository (AUR) is exposing users to stealer malware and forcing temporary package-adoption disablement. Re...
Arch Linux AUR malicious package takeover campaign
CampaignHow related: “Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.
About this happening: A malicious package takeover campaign in the Arch User Repository (AUR) is exposing users to stealer malware and forcing temporary package-adoption disablement. Re...
Deps credential stealer in hijacked Arch AUR builds
Malware Activity
H score3
First: 12.06.2026 22:24
Last: 12.06.2026 22:24
Sources 1
About this happening:
Atomic Arch is a malware activity that hijacked more than 400 Arch User Repository (AUR) packages on or after June 11 and rewrote their build scripts to run npm...
Deps credential stealer in hijacked Arch AUR builds
Malware ActivityAbout this happening: Atomic Arch is a malware activity that hijacked more than 400 Arch User Repository (AUR) packages on or after June 11 and rewrote their build scripts to run npm...
Atomic-lockfile rootkit-infostealer distribution through AUR packages
Malware Activity
H score3
First: 12.06.2026 20:03
Last: 12.06.2026 20:03
Sources 1
About this happening:
AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...
Atomic-lockfile rootkit-infostealer distribution through AUR packages
Malware ActivityAbout this happening: AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...
AUR package-hijacking campaign delivering atomic-lockfile
Campaign
H score11
First: 12.06.2026 20:03
Last: 12.06.2026 20:03
Sources 1
About this happening:
AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...
AUR package-hijacking campaign delivering atomic-lockfile
CampaignAbout this happening: AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...
Timeline
-
01.08.2026 00:38 2 articles · 1h ago
Arch Linux AUR two-stage infostealer malware activity
Initial DisclosureThe first stage of the AUR-delivered loader checks for debuggers, sandboxes, virtual machines, and CI/CD environments before setting up systemd and cron persistence. It then uses a disguised Tor client to retrieve the second-stage payload from an .onion server.
Show sources
- Arch Linux disables AUR package adoption to stop malware flood — www.bleepingcomputer.com — 01.08.2026 00:38
- Arch Linux disables AUR package adoption to stop malware flood — www.bleepingcomputer.com — 01.08.2026 00:38