Threats · 90 days ago
The compromise is in the build step, not the package name. A trusted-looking PKGBUILD can pull attacker code during a normal local build, so the user’s own workstation becomes the execution point and the compromise can outlive a package cleanup. The usual “check the package and remove it” response misses that the malicious code may already have run outside the package manager.
This has widened from tampering with abandoned AUR recipes to active cleanup and continued seeding. Arch froze new AUR signups to slow abuse while more than 1,500 malicious packages were published, and the attackers shifted some installs from NPM-based paths to Bun-based ones. The malware has been tied to credential and secret theft, and on systems with elevated privileges it can try eBPF-based persistence and hiding.
The practical break is that community-maintained build instructions now have to be treated like executable code. Any workstation that built an affected package should be assumed to have handled attacker-controlled logic, not just a bad artifact.
4 sources covering this story
Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages
Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR.
Risky Bulletin: Arch Linux supply chain attack hits 1,900 packages
Almost 2,000 Arch Linux packages have been infected with malware in a supply chain attack, FISA surveillance powers expire for the first t [Read More
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Attackers hijacked 400+ Arch Linux AUR packages to run a Rust credential stealer, with optional eBPF rootkit support on root systems.
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Attackers hijacked 400+ Arch Linux AUR packages to run a Rust credential stealer, with optional eBPF rootkit support on root systems.
Over 400 Arch Linux packages compromised to push rootkit, infostealer
More than 400 packages in the Arch User Repository (AUR) are distributing a Linux rootkit and infostealer malware targeting credentials and access tokens.
Part of the PlainSec briefing for 2026-06-15