Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Attackers compromised more than 400 Arch User Repository packages by altering build scripts to install a Rust credential stealer during package builds. The campaign, tracked as Atomic Arch, also used a second wave with js-digest and targeted developer secrets, system persistence, and optional eBPF rootkit hiding. #AtomicArch #AUR #atomic-lockfile #js-digest #Sonatype-2026-003775

Keypoints

  • More than 400 AUR packages were hijacked through malicious build script changes.
  • The attack installed a Rust-based stealer that harvests browser, GitHub, npm, SSH, and Vault secrets.
  • Malicious builds used atomic-lockfile and a second wave used js-digest.
  • The payload can create systemd persistence and optionally load an eBPF rootkit when run as root.
  • Users should inspect recent AUR installs, rotate exposed credentials, and reinstall affected systems from trusted media if root execution occurred.

Read More: https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html