Heise.De Over 400 Arch Linux AUR Packages Compromised in Supply Chain Attack
Article Content
- •Over 400 Arch Linux AUR packages compromised with malware targeting credentials.
- •Attackers exploited orphaned packages to inject malicious npm dependencies.
- •Arch maintainers are conducting a large-scale deletion campaign to remove malicious updates.
A significant supply chain attack has compromised over 400 packages in the Arch User Repository (AUR), with attackers injecting malicious build scripts that deploy credential-stealing malware and rootkits. The campaign, dubbed 'Atomic Arch', was identified around June 11, 2026, and exploits the AUR's mechanism for adopting orphaned packages. Attackers spoofed trusted publishers to modify package descriptions, adding dependencies for the npm package 'atomic-lockfile', which contains a Linux ELF payload capable of stealing sensitive information. The Arch Linux community is actively working to delete malicious updates and ban the accounts involved. Users are advised to treat affected systems as compromised and to monitor for unusual activity. The incident underscores the risks associated with community-maintained repositories.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (26)
Following this threat?
Track Atomic-lockfile in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
North Korean Hackers Target Rust Developers with Job Scam North Korean threat actors are conducting a social engineering campaign targeting Rust developers and crate maintainers. The attackers lure victims into video calls under the pretense of job offers, tricking them into installing malware or executing malicious commands. The Rust Project's crates.io team issued a…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…