Over 400 packages in the Arch User Repository (AUR) have been compromised to distribute a Linux rootkit and infostealer malware. Attackers spoofed trusted publishers and hijacked orphaned packages, modifying PKGBUILD scripts to install a malicious npm package called atomic-lockfile. This package drops a Linux ELF binary with credential-stealing capabilities targeting GitHub tokens, SSH keys, browser cookies, Slack, Discord, Teams, Telegram data, and more. An optional eBPF rootkit component can hide processes, files, and network interfaces at the kernel level. AUR maintainers are removing malicious commits and banning responsible accounts. Affected users are advised to rotate all credentials and consider a full reinstall, as rootkits may survive standard cleanup.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
180.4K Impressions7 Comments