Atomic Arch Campaign Used Compromised AUR Packages to Deliver an Infostealer

· Original article ↗

Summary

Attackers altered more than 1,900 orphaned Arch User Repository packages to fetch malicious npm or Bun dependencies. The payload stole developer credentials, established persistence and could hide activity with an eBPF rootkit.

Key points

  • From June 9–17, 2026, attackers adopted orphaned AUR packages and changed build hooks or install logic; Arch’s official repositories were not compromised.
  • The campaign used atomic-lockfile, js-digest and obfuscated Bun commands to bring in a Rust ELF payload through package installation.
  • The infostealer targeted browser data, SSH keys, developer and CI/CD tokens, chat sessions, cloud and container credentials, VPN files and cryptocurrency wallets.
  • The payload installed a persistent systemd service and exfiltrated data to a Tor C2 and to temp.sh; with sufficient privileges, it could use eBPF to hide processes, files and sockets.
  • The affected-package list reached 1,937 names and was still incomplete; the article advises treating hosts that updated affected AUR packages during the incident window as compromised.
  • Recommended response includes cross-checking installed packages, rotating exposed credentials and rebuilding suspected hosts from known-good media; yay 13.0 added package-age visibility and hook filtering.

Article Details

Attack Vectors
  • An attacker adopted orphaned Arch User Repository packages and modified their PKGBUILD, hook, or .install logic to fetch malicious npm or Bun packages during builds.
  • The first wave installed atomic-lockfile alongside legitimate packages minimist and chalk. Later waves used js-digest, lockfile-js, and nextfile-js, including quote-split Bun commands and $IFS separators to evade simple string matching.
  • atomic-lockfile used a preinstall hook to execute a Rust-compiled Linux ELF binary that harvested credentials and other data. The binary installed a persistent systemd service and, when it had sufficient privileges, deployed an eBPF rootkit to conceal activity.
  • The article assesses several deleted AUR packages as attacker-created typosquatting lures, particularly packages resembling cryptocurrency-wallet names. It notes uncertainty about the origin of other deleted packages.
Defensive Notes
  • Identify AUR packages installed or updated between June 9 and June 17, 2026, and compare them with the live Arch-maintained affected-package list.
  • Search build caches, source caches, and home directories for atomic-lockfile, js-digest, lockfile-js, nextfile-js, and src/hooks/deps.
  • Check /sys/fs/bpf/ for the rootkit maps hidden_pids, hidden_names, and hidden_inodes. On a host affected by the rootkit, do not rely on ordinary file, process, or socket listings.
  • Investigate Tor-related egress and POST activity to temp.sh from developer workstations, and retain local logs that can show package installation activity.
  • If compromise is indicated, rotate exposed credentials and rebuild the host from known-good media rather than relying on package removal.

Indicators of compromise

TypeIndicatorContext
MD542b59fdbe1b72895b2951412222ebf40MD5 of the Wave 1 credential-stealing ELF payload.
SHA2566144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98bSHA-256 of the Wave 1 credential-stealing ELF payload.
SHA2567883bda1ff15425f2dbe622c45a3ae105ddfa6175009bbf0b0cad9bf5c79b316SHA-256 identified in the hunt list as a Wave 2 ELF payload.

MITRE ATT&CK

T1014 · RootkitWith sufficient privileges, the payload deployed an eBPF rootkit to hide processes, files, and network sockets.T1027 · Obfuscated Files or InformationLater AUR build commands used quote-splitting and $IFS separators, while the payload stored its Tor C2 address as an XOR-encoded blob.T1041 · Exfiltration Over C2 ChannelCollected data was sent by POST /api/agent to the Tor C2.T1195.001 · Compromise Software Dependencies and Development ToolsCompromised AUR build logic pulled malicious npm or Bun packages, including atomic-lockfile and js-digest, as dependencies.T1195.002 · Compromise Software Supply ChainThe attacker adopted orphaned AUR packages and changed their build or install logic to fetch a malicious payload.T1539 · Steal Web Session CookieThe payload targeted browser cookies and session tokens.T1543.002 · Systemd ServiceThe payload installed a systemd service configured with Restart=always and RestartSec=30.T1552.001 · Credentials In FilesThe payload targeted credentials stored in files, including npm authentication tokens in ~/.npmrc.T1552.004 · Private KeysThe payload collected SSH private keys from developer machines.T1555.003 · Credentials from Web BrowsersThe payload targeted saved browser passwords and other browser credential material.T1567.002 · Exfiltration to Cloud StorageThe payload used POST /upload to the public file-sharing service temp.sh as a secondary exfiltration route.T1622 · Debugger EvasionThe payload checked for debuggers using PTRACE_ATTACH and PTRACE_SEIZE.

People

Malware

Products

Tools

Related Articles