Arch Linux has temporarily disabled AUR package adoption after a wave of malicious takeovers led to infected packages being pushed through the repository. The campaign, which started with openconnect-sso and may involve over 200 packages, uses a Tor-based two-stage payload to steal credentials, spread via SSH, and maintain persistence. #ArchLinux #AUR #openconnect-sso #IFIN
Keypoints
- Arch Linux temporarily disabled AUR package adoption.
- Malicious takeovers and follow-up commits increased across the repository.
- IFIN linked the campaign to a two-stage Linux payload launched through Tor.
- The stealer targets browser data, wallets, secrets, SSH keys, and API keys.
- The campaign may have spread to more than 200 AUR packages, including popular ones.