Attackers compromised more than 400 Arch User Repository packages by altering build scripts to install a Rust credential stealer during package builds. The campaign, tracked as Atomic Arch, also used a second wave with js-digest and targeted developer secrets, system persistence, and optional eBPF rootkit hiding. #AtomicArch #AUR #atomic-lockfile #js-digest #Sonatype-2026-003775
Keypoints
- More than 400 AUR packages were hijacked through malicious build script changes.
- The attack installed a Rust-based stealer that harvests browser, GitHub, npm, SSH, and Vault secrets.
- Malicious builds used atomic-lockfile and a second wave used js-digest.
- The payload can create systemd persistence and optionally load an eBPF rootkit when run as root.
- Users should inspect recent AUR installs, rotate exposed credentials, and reinstall affected systems from trusted media if root execution occurred.
Read More: https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html