2 min read

Arch Linux suspends AUR adoption after malware surge

Arch Linux suspended AUR package adoption after malware allegedly spread through more than 200 packages using hijacked or orphaned projects.

Image: BleepingComputer

Arch Linux has temporarily disabled adoption of packages in the Arch User Repository (AUR) after a surge of malicious takeovers involving existing projects.

Robin Candau, an Arch Linux contributor, announced the move on the distribution’s mailing list and said adoption will remain suspended while the project works on a solution.

“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation.”

Robin Candau, Arch Linux contributor

Candau urged users to report suspicious adoption events or commits that have not yet been handled, and to remain vigilant.

Two-stage malware campaign targets AUR users

Independent Federated Intelligence Network (IFIN) said the latest campaign began on July 29, starting with the openconnect-sso package. The researchers found similarities to an earlier campaign, including the use of the Tor network to stage malware.

The infection uses two stages:

Recommended reading

Claude models escaped tests and reached real systems

  • A loader checks for debuggers, sandboxes, virtual machines, and CI/CD environments before creating systemd services and cron jobs for persistence.
  • It downloads a Tor client disguised as dbus-daemon, which retrieves the second-stage payload from an .onion server.

The second stage is a Rust-based infostealer for Linux x86_64. IFIN described it as combining information-stealing, remote administration (RAT), and SSH-worm capabilities. It targets browser credentials, cryptocurrency wallets, password-manager data, cloud and developer secrets, AI service API keys, SSH keys, and messaging-platform tokens.

Attackers can also execute commands through an encrypted Tor channel. The malware can spread laterally by using stolen SSH keys to copy and run itself on other systems.

More than 200 packages allegedly affected

A Reddit user tracking the campaign alleges that it has expanded to more than 200 AUR packages, using either compromised maintainer accounts or the adoption of orphaned packages. The alleged targets include boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server.

The status of those packages has not been independently confirmed, and a complete list of the 200 packages believed to be malicious was not available when the report was published.

The incident follows a separate campaign in June that affected more than 400 AUR packages, distributing a Linux rootkit and information-stealing malware.

Article image
Article image
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

/ Keep reading