Attackers hijacked over 1,500 packages in Arch Linux's AUR by adopting orphaned packages and rewriting their build scripts to install a credential stealer. The malware, a Rust binary, harvests browser cookies, session tokens, GitHub/npm tokens, SSH keys, Docker logins, and more, exfiltrating data over Tor. The attack exploited the AUR's trust model rather than any technical vulnerability — spoofed git commit data made changes appear legitimate. An optional eBPF component hides the malware if root access is available. Arch's official repos were unaffected. With ~13,000 orphaned AUR packages remaining, the structural risk persists. Users are advised to read build scripts before compiling and treat recently adopted packages with suspicion.
1.4K Impressions