Atomic Arch npm Campaign Adds Malicious Dependency
ID: 858db864-e3a9-5e2f-8003-85dbc9c60c04
STIX ID: report--858db864-e3a9-5e2f-8003-85dbc9c60c04
Feed Name: Security Boulevard
Threat Score
Sonatype researchers disclosed the "Atomic Arch" campaign where attackers compromise abandoned AUR packages by altering PKGBUILDs to pull in a malicious npm dependency (atomic-lockfile). The malicious package contains a Linux payload designed for credential harvesting, stealth/anti-debugging, and potential data exfiltration, representing a supply‑chain threat that leverages existing developer trust.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
