Arch Linux Suspends AUR Package Adoption Amid Malware Campaign

Arch Linux temporarily disables the adoption of orphaned packages on the Arch User Repository (AUR) after a surge of malicious takeovers hits the platform. Contributor Robin Candau announces the measure on the project's mailing list, explaining that the suspension remains in effect while the team handles an ongoing influx of malicious package adoptions and commits. Users are urged to stay vigilant and report any suspicious activity that has not yet been addressed.

Independent Federated Intelligence Network (IFIN) traces the campaign back to July 29, when it begins with the package openconnect-sso. The attack uses a two-stage infection process: a first-stage loader that evades detection by checking for debuggers, sandboxes, and virtual machines, followed by a Rust-based infostealer that targets browser credentials, cryptocurrency wallets, password manager data, cloud secrets, API keys, and SSH keys. The payload also functions as a remote access trojan and an SSH worm capable of lateral movement across systems.

The campaign quickly expands to over 200 AUR packages, according to a Reddit user tracking the attacks, spreading through compromised maintainer accounts and orphaned package adoptions. The latest wave follows a similar incident in June that distributed a Linux rootkit and info-stealer through more than 400 packages. Both campaigns rely on the Tor network for staging and command-and-control communications, highlighting a persistent threat to the community-driven repository that Arch Linux relies on for user-contributed software.

Read More at the original source →