NEWS In Arch Linux found a malware-matreshka: a package inside the package, and at the very bottom - a password thief

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,341
400 packets, one old loophole – and access to everything: from browser to cryptowalls.
1781446415649.png
In Arch User Repository found a large-scale attack on the supply chain: the attackers gained control over more than 400 packages and changed their assembly scenarios. After that, when installing or updating an infected package, a styler was launched on the user’s machine to steal the secrets of developers. Official Arch Linux repositories were not affected, the problem affected AUR - the user directory of packages that supports the community.

The AUR works differently than a conventional distribution repository. The user often receives not a ready-made program, but a collection recipe: where to download the source code, what dependencies to establish and which commands to perform. It was in these recipes that the attackers added malicious commands. The names of the packages, the history of projects and the accumulated trust in them remained the same.

Sonatype named the Atomic Arch campaign. The attackers were looking for abandoned packages that no longer had an active accompanying person. In the AUR, such projects can be taken up for support, and this was used by attackers: they took old packages, changed PKGBUILD or .install installation scenarios and waited for users to start the assembly themselves.

The main danger is that the attack did not use a vulnerability in the Arch Linux and did not require the hacking of the distribution infrastructure. The user saw a familiar package, updated or collected it in the usual way, and the malicious code was launched already at the assembly stage. The incident is unpleasant for this reason: the trust in the name of the package and its old history was stronger than checking who accompanies the project now.

In the modified scripts, the installation of the atomic-lockfile package from NPm was added. At first glance, the team could look like an ordinary attitude of addiction, especially next to the added legitimate packages for disguise. But in the atomic-lockfill 1.4.2 was a pre-installing script, which ran an attached executable Linux file named deps. After assembling the infected AUR-package, this file has already worked on the user's machine.

Among the confirmed examples mentioned alvr and premake-git. At first, the Sonatype talked about more than 20 compromised packages, but then community members and discussion in the Arch-general newsletter quickly expanded the list. According to inspections of the AUR mirror, the number of suspicious packages increased to about 408, and the final list continues to be specified.

The executable deps file was disassembled by an independent researcher Whanos. According to his analysis, it is a stylish style written on Rust, focused on the workstations of developers and assemblage environments. It collects data from Chromium-based browsers, including Chrome, Edge and Brave, pulls sessions from applications on Electron like Slack, Discord and Microsoft Teams, looking for GitHub tokens, anthrop, HashiCorp Vault, OpenAI and ChatGPT access data, SSH keys, keys, command shell history, Docker account.VPN

The stolen files were sent via HTTP to temp.sh, and the control commands went through the hidden Tor service with a local proxy. To fix the system, the styler created a systemd service with automatic restart. When running root rights, he copied itself into a directory inside /var/lib and created a service file in /ett/systemd/system/system/. Without administrator rights, he used the user's home directory and systemd user service in ~//.config/systemd/user/.

A separate interest was caused by rootkite on eBPFeBPF, which was mentioned in the early analysis. Its role is important not to exaggerate: this component does not give the administrator right style and is not used to increase privileges. It only boots when the malicious file is already running with root rights and got the necessary features. But if the rootkite has been activated, it can hide processes, process names and network sockets from standard tools, and also interfere with debugging.

That is why the simple removal of the infected AUR-package is not enough. A packet manager can remove the files you know about. But if the styler has already been launched, especially with root rights, the system can no longer be trusted. In this case, it is safer to consider the machine compromised, change the keys and tokens, and with the possible activation of rootkite - to re-installation of the system from a trusted medium.

The analysis also mentions the second file associated with monero-wallet-gui. It has not yet been dismantled completely, but the researchers consider it as a possible miner Monero. This combination - theft of secrets, fixing in the system and additional rootkit on the eBPF - makes the campaign more dangerous than a regular malicious package from a user repository.

Later there was a second wave of attack. It used not atomic-lockfil, but the installation of js-digest through the bun. This activity is associated with a separate set of accounts that community members compared to the same author of the npm package as the atomic-lockffile. The full scale of the second wave is still considered, but users are advised to check the traces of both dependencies.

Arch developers remove malicious commits, block related accounts and ask users to report suspicious packages in the newsletter. At the same time, the published lists can not be considered final: some of the changes are already rolling back, some of the packages could change again, and new matches continue to be found through the search through the AUR mirrors.

Users of Arch Linux who have been installing or updated AUR-packages from June 11 should check them on the current lists of the affected projects. Particular attention should be paid to the packages that have recently changed the accompanying person, have not been updated for a long time, and then suddenly received new installation or commands to load dependencies. If the infected package managed to collect and run, you need to proceed from the fact that browser sessions, SSH keys, GitHub tokens and NPm, Docker, Vault, messengers and cloud services could be stolen.

To detect the SHA-256 of the main malicious file: 6144d43f8 fara03867877b8b812c8251275b9157f157,578c458c457c48c98c98c98c98b. A complete set of indicators, including the address of the hidden Tor service, is given in the analysis of ioctl.fail. Sonatype tracks the campaign as the Sonatype-2026-003775 with a CVSS 8.7 rating. CVE was not assigned for an attack because it is not a vulnerability in a specific program, but a compromising packets through the AUR tracking model.

A similar scheme was already found in 2018, when the attackers took the abandoned PDF viewer package and added malicious code. In 2026, the same technique was simply scalable: instead of trying to deceive the user with a similar name, the attackers took real old packets.

The attack shows the weak point of the AUR well. The user repository is convenient precisely because it has a lot of software and a low threshold for adding packages. But the same openness requires the habit of reading PKGBUILD and .install files before building. If the package recently changed the accompanying person or suddenly began to execute new installation commands, it should be treated as an unfamiliar project, even if his name has long been in the AUR.
 

No bugett

Well-known member
Member
Joined
Aug 26, 2026
Messages
78
Reaction score
1
(NON VBV CC)





CC TO BTC METHOD





CASHAPP& (Zelle) BANK TRANSFER available ($50 for $1.6k) @nobudgett1





Auto Adds Credit Cards


Linkables Avaliable





Live dumps / Fullz and Cc’s Avaliable





No otp ccs for Payment link (Non vbv)





Works in applePay, GPay, PayPal, Cashapp, booking and more….


Crypto method+bin





CVV / CLONE CARDS


LINKABLES


AMAZON CCS


EXODUS CCS


CASH APP CC





Updated methods available





Replacement or refund if items are dead


(Don't message me if you are not ready)





To purchase - @nobudgett1





Telegram channel : https://t.me/+CuDZ9auFpRc3Mjkx
 
5,854Threads
77,670Messages
5,876Members
DARKWEBHUTMANFLADHLatest member
Top Bottom