Over 400 Arch Linux packages compromised to push rootkit, infostealer

Over 400 Arch Linux packages compromised to push rootkit, infostealer

More than 400 Arch User Repository packages were found distributing a Linux rootkit and infostealer that steal credentials, access tokens, and developer secrets from Arch users. Attackers spoofed a trusted publisher and hijacked orphaned AUR packages to deliver the malicious atomic-lockfile package and a payload with eBPF rootkit capabilities. #ArchUserRepository #atomic-lockfile #IndependentFederatedIntelligenceNetwork #Sonatype #ArchLinux

Keypoints

  • Over 400 AUR packages were used to spread rootkit and infostealer malware.
  • Attackers spoofed a trusted publisher and hijacked orphaned packages on Arch Linux.
  • The malicious atomic-lockfile package was installed through preinstall or post-install scripts.
  • The Linux payload targeted browser data, GitHub, SSH, Vault, Slack, Discord, and Teams.
  • Arch users are advised to review indicators of compromise, rotate credentials, and reinstall if compromised.

Read More: https://www.bleepingcomputer.com/news/security/over-400-arch-linux-packages-compromised-to-push-rootkit-infostealer/