Find notable cyber news and cases, enriched with sources, timelines, and signals.

Arch Linux AUR two-stage infostealer malware activity

Malware Activity
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

AUR-delivered Linux malware is now using a two-stage infection chain that installs persistence and fetches a Tor-routed payload, increasing the risk of credential theft, wallet theft, and lateral spread on affected systems. The second-stage payload is a Rust-based infostealer with RAT and SSH worm features. The activity has been tied to malicious package adoptions in the Arch User Repository and broader package spread.

Related Happenings

Arch Linux AUR malicious package takeover campaign

Campaign
H score47 First: 01.08.2026 00:38 Last: 01.08.2026 00:38 Sources 1

How related: “Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.

About this happening: A malicious package takeover campaign in the Arch User Repository (AUR) is exposing users to stealer malware and forcing temporary package-adoption disablement. Re...

Deps credential stealer in hijacked Arch AUR builds

Malware Activity
H score3 First: 12.06.2026 22:24 Last: 12.06.2026 22:24 Sources 1

About this happening: Atomic Arch is a malware activity that hijacked more than 400 Arch User Repository (AUR) packages on or after June 11 and rewrote their build scripts to run npm...

Atomic-lockfile rootkit-infostealer distribution through AUR packages

Malware Activity
H score3 First: 12.06.2026 20:03 Last: 12.06.2026 20:03 Sources 1

About this happening: AUR packages are distributing the atomic-lockfile Linux rootkit and infostealer through compromised build scripts, with more than 400 packages reported and the o...

AUR package-hijacking campaign delivering atomic-lockfile

Campaign
H score11 First: 12.06.2026 20:03 Last: 12.06.2026 20:03 Sources 1

About this happening: AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...

Timeline

  1. 01.08.2026 00:38 2 articles · 1h ago

    Arch Linux AUR two-stage infostealer malware activity

    Initial Disclosure

    The first stage of the AUR-delivered loader checks for debuggers, sandboxes, virtual machines, and CI/CD environments before setting up systemd and cron persistence. It then uses a disguised Tor client to retrieve the second-stage payload from an .onion server.

    Show sources