logo

Arch Linux pulls AUR packages that installed Chaos RAT malware

ID: f91ff055-a410-586a-a785-e22a5a49fee2

STIX ID: report--f91ff055-a410-586a-a785-e22a5a49fee2

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-07-18

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Arch Linux removed three malicious AUR packages (librewolf-fix-bin, firefox-patch-bin, zen-browser-patched-bin) uploaded by a single user that used an external GitHub repository to deploy the open-source CHAOS RAT to Linux systems; archived copies and community reporting identified the malware and its C2 server (130.162.225.47:8080), and users are advised to remove the packages and check for a suspicious systemd-initd executable in /tmp.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.