More than 400 Arch User Repository packages were found distributing a Linux rootkit and infostealer that steal credentials, access tokens, and developer secrets from Arch users. Attackers spoofed a trusted publisher and hijacked orphaned AUR packages to deliver the malicious atomic-lockfile package and a payload with eBPF rootkit capabilities. #ArchUserRepository #atomic-lockfile #IndependentFederatedIntelligenceNetwork #Sonatype #ArchLinux
Keypoints
- Over 400 AUR packages were used to spread rootkit and infostealer malware.
- Attackers spoofed a trusted publisher and hijacked orphaned packages on Arch Linux.
- The malicious atomic-lockfile package was installed through preinstall or post-install scripts.
- The Linux payload targeted browser data, GitHub, SSH, Vault, Slack, Discord, and Teams.
- Arch users are advised to review indicators of compromise, rotate credentials, and reinstall if compromised.