logo

Atomic Arch npm Campaign Adds Malicious Dependency

ID: 858db864-e3a9-5e2f-8003-85dbc9c60c04

STIX ID: report--858db864-e3a9-5e2f-8003-85dbc9c60c04

Feed Name: Security Boulevard

Threat Score
72/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

Author: Sonatype Security Research Team

...
...

Sonatype researchers disclosed the "Atomic Arch" campaign where attackers compromise abandoned AUR packages by altering PKGBUILDs to pull in a malicious npm dependency (atomic-lockfile). The malicious package contains a Linux payload designed for credential harvesting, stealth/anti-debugging, and potential data exfiltration, representing a supply‑chain threat that leverages existing developer trust.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.