#AtomicArch
Over 400 Arch Linux AUR packages were hijacked via malicious build scripts to install a Rust infostealer, stealing browser, GitHub, npm, SSH, and Vault secrets. #AtomicArch #AUR #eBPF
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Attackers compromised more than 400 Arch User Repository packages by altering build scripts to install a Rust credential stealer during package builds. The campaign, tracked as Atomic Arch, also used a second wave with js-digest and targeted developer secrets, system persistence, and optional eBPF rootkit hiding. #AtomicArch #AUR #atomic-lockfile #js-digest #Sonatype-2026-003775...
www.hendryadrian.com
June 13, 2026 at 2:00 AM
📣🚨 Over 20 Linux packages were compromised in the #AtomicArch campaign, which abuses AUR ownership transfers to drop rootkit-like malware.

Read: hackread.com/atomic-arch-...

#CyberSecurity #Linux #Malware #SupplyChainAttack
Atomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver Malware
Over 20 Linux packages were compromised in the Atomic Arch campaign, which abuses AUR ownership transfers to drop rootkit-like malware.
hackread.com
June 12, 2026 at 6:37 PM
Learn how to use the Arch User Repository (AUR) safely. Discover the lessons from the June 2026 AUR malware attack and protect your Arch Linux system.

Full details here: ostechnix.com/use-the-aur-...

#ArchUserRepository #AUR #ArchLinux #Security #Malware #SupplyChainAttack #AtomicArch #Linux
How to Use the AUR Safely | Arch Linux AUR Security - OSTechNix
Learn how to use the Arch User Repository (AUR) safely. Discover the lessons from the June 2026 AUR malware attack and protect your Arch Linux system.
ostechnix.com
July 16, 2026 at 2:21 PM
eBPF rootkits like VoidLink and LinkPro hide sockets and kill debuggers with rare helpers. Defenders can spot them early by fingerprinting loaded programs for bpf_probe_write_user, bpf_override_return, and bpf_send_signal. #eBPF #Rootkits #Linux
Detection primitives for eBPF rootkits
Linux eBPF rootkits such as VoidLink, LinkPro, and the Atomic Arch campaign use rare helpers to hide sockets, obscure their own programs, and kill ptrace-based debuggers before the kernel finishes processing them. The article shows that defenders should focus on load-time fingerprinting of eBPF programs because helpers like bpf_probe_write_user(), bpf_override_return(), and bpf_send_signal() reveal malicious intent before the rootkit can conceal itself. #VoidLink #LinkPro #AtomicArch #bpf_probe_write_user #bpf_override_return #bpf_send_signal
www.hendryadrian.com
July 28, 2026 at 8:30 AM
Attackers hijacked 1,900+ orphaned Arch User Repository packages to spread atomic-lockfile, a fake npm payload that stole developer credentials and could lead to an eBPF rootkit. #AUR #AtomicArch #ArchLinux
Atomic Arch: orphaned AUR packages turned zombie infostealer
Between June 9 and June 17, 2026, attackers abused more than 1,900 orphaned Arch User Repository packages to deliver a fake npm payload called atomic-lockfile that stole developer credentials and could escalate into an eBPF rootkit. The campaign also included bun-based variants, Tor-backed exfiltration, and impersonation of legitimate maintainer identities such as arojas and the herbsobering npm account. #atomic-lockfile #js-digest #nextfile-js #AUR #herbsobering #arojas
www.hendryadrian.com
July 22, 2026 at 12:00 AM
Adopting an orphaned Arch AUR package could hand attackers your SSH keys - and a kernel rootkit if you built as root. https://intel.threadlinqs.com/threat/TL-2026-1498 #ThreatIntel #Tor #Atomic #AtomicArch
July 18, 2026 at 9:44 PM
400+ Arch Linux AUR packages were hijacked via build script tampering to spread Atomic Arch, a Rust stealer targeting dev secrets, SSH keys, browser data, and cloud tokens. Optional eBPF rootkit and systemd persistence found. #ArchLinux #AtomicArch
400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
Attackers compromised more than 400 Arch User Repository packages and altered their build scripts to deliver the Atomic Arch credential stealer during package builds. The campaign also used the malicious npm package atomic-lockfile and a second wave involving js-digest, with some payloads able to install an optional eBPF rootkit and persistence...
www.hendryadrian.com
June 12, 2026 at 9:00 PM
I just ousted @atomicarch as the mayor of AKA Music on @foursquare! <a href="http://4sq.com/7bpi6E" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">http://4sq.com/7bpi6E
AKA Music
Record Store in Philadelphia, PA
4sq.com
November 6, 2024 at 8:18 PM
⚠️ Arch users have certainly heard of #atomicarch : attackers hijacked orphaned AUR packages, slipping credential-stealing #malware into PKGBUILD post-install hooks. Official repos are safe - only AUR is hit. A community list of compromised packages has since grown to 1935 entries […]
Original post on chaos.social
chaos.social
June 19, 2026 at 8:09 PM
New YARA rules for the #AtomicArch supply-chain attack

~1,500 #ArchLinux AUR packages were reportedly hijacked and backdoored to deploy a Rust infostealer and eBPF rootkit via malicious PKGBUIL…

🔁 RT @nextronresearch | reposted by @cyb3rops
https://x.com/nextronresearch/status/2066619871345934447
June 15, 2026 at 9:29 PM