logo

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

ID: ede81f3c-b835-549b-b85b-480c3cda35f8

STIX ID: report--ede81f3c-b835-549b-b85b-480c3cda35f8

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

Author: [email protected] (The Hacker News)

...
...

Attackers adopted abandoned AUR packages and altered their build scripts to install a malicious npm package that runs a Rust credential stealer; over 400 packages were reported affected. The payload exfiltrates browser and Electron session data, GitHub/npm/Vault/OpenAI tokens, SSH keys, container credentials, and more, persists via systemd, and can optionally load an eBPF rootkit if executed with root privileges. Community trackers and Sonatype provided detection lists and indicators (including a SHA-256) and advise checking any AUR packages built or updated on/after June 11, rotating compromised credentials, hunting for persistence, and reinstalling systems if root compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.