Skip to main content
Mallory
Back to intelligence
package-repository-poisoningloader-delivery-mechanismopen-source-dependency-vulnerability

Malicious Commits in Arch Linux AUR Packages Pulled npm-Based Payloads

Updated 13h agoFirst seen Jun 12, 202611 sources

Arch Linux users are responding to a malware incident in the Arch User Repository (AUR) after multiple user-contributed packages were modified with malicious commits that attempted to fetch npm-based payloads during installation. Reports on the aur-general mailing list and a dedicated incident thread indicate the changes inserted unexpected npm commands and behavior unrelated to the original software, with the alvr package cited as a prominent example and atomic-lockfile named among the npm packages involved.

Arch maintainers and contributors have been removing the malicious changes, tracking affected packages, and banning associated accounts while the full scope remains under investigation. The incident is reported to be limited to the AUR and does not affect Arch Linux’s official package repositories; users are being urged to avoid blindly updating AUR packages and to review PKGBUILD diffs, newly added .install files, and any unexpected npm dependencies before installing updates.

Share:
Malicious Commits in Arch Linux AUR Packages Pulled npm-Based Payloads
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jun 12, 20262d ago

Arch says Atomic Arch incident is under control; affected package count reaches 1,579

Arch Linux developers said they had deleted all malicious commits they were aware of and believed the AUR malware incident was under control. A cited list put the number of affected AUR packages at 1,579, indicating the scope had grown beyond earlier estimates of 900+ packages.

Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Affected Packages - Phoronix

Second Atomic Arch wave uses bun/js-digest to deliver new ELF payload

Reporting on the Atomic Arch supply-chain campaign said attackers launched a second wave that replaced the earlier npm-based payload chain with `bun install js-digest`, delivering a different malicious ELF. The update indicated the campaign expanded beyond the initial `atomic-lockfile` infostealer/rootkit delivery method.

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Report says Atomic Arch hit 900+ AUR packages with eBPF rootkit

A new report on the 'Atomic Arch' supply-chain campaign said more than 900 AUR packages were backdoored after attackers adopted orphaned packages and modified PKGBUILDs to install malicious npm packages. The report also described expanded malware capabilities, including a Rust-based credential stealer with an eBPF rootkit, systemd persistence, Tor-based communications, and possible Monero cryptomining staging.

Atomic Arch: 900+ AUR Packages Backdoored with eBPF RootkitCopy | The CyberSec Guru

Arch Linux announces active mitigation for malicious AUR packages

Arch Linux said it was actively tracking malicious AUR commits and taking steps to prevent additional malicious updates from being pushed. The project warned users that AUR account creation, package updates, and package adoption or creation could be disrupted during mitigation efforts and advised users to review PKGBUILD and install script changes carefully.

Arch Linux - News: Active AUR malicious packages incident
Jun 11, 20262d ago

Arch contributors begin tracking and removing affected AUR packages

Contributors opened a dedicated report thread to track affected packages, remove malicious commits, and ban related accounts. Reporting indicated the incident was limited to the AUR and did not affect Arch Linux's official package repositories.

Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages

Researchers detail 400+ compromised AUR packages in 'Atomic Arch' campaign

Researchers reported that more than 400 Arch User Repository packages were compromised in a supply chain attack dubbed 'Atomic Arch,' with attackers abusing orphan-package adoption to insert malicious PKGBUILD changes. The altered scripts fetched rogue npm packages that deployed an infostealer targeting browser credentials, SSH keys, environment variables, and cryptocurrency wallet data, while Arch maintainers reverted commits and banned the attacker accounts.

400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers

Malicious commits reported in Arch Linux AUR packages

A malware incident affecting Arch Linux's Arch User Repository was first reported on the aur-general mailing list, where user-contributed packages were found to contain malicious commits that attempted to download npm-based payloads during installation.

Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

45 LINKEDOpen in app
Threat actors
2 linked
Affected products
19 linked
Arch LinuxDiscordNpmGithubDockerPodmanChatgptBrave BrowserTorBraveSystemdTelegramMaxthonUc BrowserYandex BrowserFirefoxVaultOperaChromium
Organizations
18 linked
SonatypeGitHubDiscordHashicorpMicrosoft CorporationSlack TechnologiesOpenaiBrave SoftwareDockerGoogleRed HatSocketnpm, Inc.Monero ProjectTelegramArch LinuxTelegram Messenger Inc.Independent Federated Intelligence Network
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Malicious Commits in Arch Linux AUR Packages Pulled npm-Based Payloads | Mallory