Over 400 Arch Linux packages compromised to push rootkit, infostealer
ID: 1938c62a-7bcb-5ef0-a708-fe638198a3e9
STIX ID: report--1938c62a-7bcb-5ef0-a708-fe638198a3e9
Feed Name: Bleeping Computer
Researchers reported a supply-chain campaign in the Arch User Repository (AUR) where a malicious maintainer modified over 400 packages to run post-install scripts that fetch an npm package (atomic-lockfile). The npm package installs a Linux ELF payload named 'deps' that acts as an infostealer targeting developer credentials and tokens (GitHub, SSH, Vault, browser data, Slack/Teams/Discord/Telegram), and includes optional eBPF rootkit functionality to gain kernel-level stealth and persistence; Sonatype and independent researchers provided affected-package lists and detection/removal guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
