“Atomic Arch”: Nearly 900 AUR Packages Backdoored with a Developer-Targeting Infostealer and eBPF Rootkit

beanburrito

Active Member
Joined
May 14, 2026
Messages
138
Reaction score
202
Credits
1,055
As mentioned (but maybe overlooked by users) here, here, and here.

There's a great write up about it here:


"On June 11, someone going by the username arojas spent what was probably a quiet afternoon methodically adopting orphaned Arch User Repository packages and injecting them with malware. By the time the community caught on, 408 packages were already compromised. By the time this piece was being written, that number had crossed 900 and is still climbing.

Sonatype researchers have named the campaign Atomic Arch. It’s one of the largest AUR supply chain incidents on record, and the technical sophistication of the payload puts it well beyond your average package repository drive-by."

"If you’re not on Arch Linux, you’re not affected."

= Sections include:

How It Started: AUR’s Orphan Adoption Policy
The Infection Chain: How a PKGBUILD Becomes a Backdoor
The Payload: Meet deps
What it steals
Persistence: How It Digs In
The eBPF Rootkit: Why This Is Serious
Command and Control: Tor Onion Service
Threat Actor Infrastructure
Comprehensive Analysis
Detection & Response Guidance
What You Need to Do Right Now
The Bigger Picture


Hacker News Discussion
 
Last edited:


just checked my main system, I'm clear. thanks for the link! it's a nice writeup
 
Thanks for sharing! I did already read it and hear about it in several places. I replaced everything with either verified Flatpaks, one I'm downloading the binary directly from the source, an official appimage and one I'm pulling the source and then building it myself. For the ones that aren't Flatpaks I created a desktopfile myself so I can easily launch them, no more AUR needed.
 


Follow Linux.org

Staff online


Top