Attackers hijacked over 1,500 packages in Arch Linux's AUR by adopting orphaned packages and rewriting their build scripts to install a credential stealer. The malware, a Rust binary, harvests browser cookies, session tokens, GitHub/npm tokens, SSH keys, Docker logins, and more, exfiltrating data over Tor. The attack exploited the AUR's trust model rather than any technical vulnerability — spoofed git commit data made changes appear legitimate. An optional eBPF component hides the malware if root access is available. Arch's official repos were unaffected. With ~13,000 orphaned AUR packages remaining, the structural risk persists. Users are advised to read build scripts before compiling and treat recently adopted packages with suspicion.

4m read timeFrom thenextweb.com
Post cover image
Table of contents
An attack on trust, not a flawA trap built for developersThe cost of an open door
1.4K Impressions