Atomic Arch Campaign Used Compromised AUR Packages to Deliver an Infostealer

Summary
Attackers altered more than 1,900 orphaned Arch User Repository packages to fetch malicious npm or Bun dependencies. The payload stole developer credentials, established persistence and could hide activity with an eBPF rootkit.
Key points
- From June 9–17, 2026, attackers adopted orphaned AUR packages and changed build hooks or install logic; Arch’s official repositories were not compromised.
- The campaign used atomic-lockfile, js-digest and obfuscated Bun commands to bring in a Rust ELF payload through package installation.
- The infostealer targeted browser data, SSH keys, developer and CI/CD tokens, chat sessions, cloud and container credentials, VPN files and cryptocurrency wallets.
- The payload installed a persistent systemd service and exfiltrated data to a Tor C2 and to temp.sh; with sufficient privileges, it could use eBPF to hide processes, files and sockets.
- The affected-package list reached 1,937 names and was still incomplete; the article advises treating hosts that updated affected AUR packages during the incident window as compromised.
- Recommended response includes cross-checking installed packages, rotating exposed credentials and rebuilding suspected hosts from known-good media; yay 13.0 added package-age visibility and hook filtering.
Article Details
- Attack Vectors
- An attacker adopted orphaned Arch User Repository packages and modified their PKGBUILD, hook, or .install logic to fetch malicious npm or Bun packages during builds.
- The first wave installed atomic-lockfile alongside legitimate packages minimist and chalk. Later waves used js-digest, lockfile-js, and nextfile-js, including quote-split Bun commands and $IFS separators to evade simple string matching.
- atomic-lockfile used a preinstall hook to execute a Rust-compiled Linux ELF binary that harvested credentials and other data. The binary installed a persistent systemd service and, when it had sufficient privileges, deployed an eBPF rootkit to conceal activity.
- The article assesses several deleted AUR packages as attacker-created typosquatting lures, particularly packages resembling cryptocurrency-wallet names. It notes uncertainty about the origin of other deleted packages.
- Defensive Notes
- Identify AUR packages installed or updated between June 9 and June 17, 2026, and compare them with the live Arch-maintained affected-package list.
- Search build caches, source caches, and home directories for atomic-lockfile, js-digest, lockfile-js, nextfile-js, and src/hooks/deps.
- Check /sys/fs/bpf/ for the rootkit maps hidden_pids, hidden_names, and hidden_inodes. On a host affected by the rootkit, do not rely on ordinary file, process, or socket listings.
- Investigate Tor-related egress and POST activity to temp.sh from developer workstations, and retain local logs that can show package installation activity.
- If compromise is indicated, rotate exposed credentials and rebuild the host from known-good media rather than relying on package removal.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| MD5 | 42b59fdbe1b72895b2951412222ebf40 | MD5 of the Wave 1 credential-stealing ELF payload. |
| SHA256 | 6144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98b | SHA-256 of the Wave 1 credential-stealing ELF payload. |
| SHA256 | 7883bda1ff15425f2dbe622c45a3ae105ddfa6175009bbf0b0cad9bf5c79b316 | SHA-256 identified in the hunt list as a Wave 2 ELF payload. |
MITRE ATT&CK
T1014 · RootkitWith sufficient privileges, the payload deployed an eBPF rootkit to hide processes, files, and network sockets.T1027 · Obfuscated Files or InformationLater AUR build commands used quote-splitting and $IFS separators, while the payload stored its Tor C2 address as an XOR-encoded blob.T1041 · Exfiltration Over C2 ChannelCollected data was sent by POST /api/agent to the Tor C2.T1195.001 · Compromise Software Dependencies and Development ToolsCompromised AUR build logic pulled malicious npm or Bun packages, including atomic-lockfile and js-digest, as dependencies.T1195.002 · Compromise Software Supply ChainThe attacker adopted orphaned AUR packages and changed their build or install logic to fetch a malicious payload.T1539 · Steal Web Session CookieThe payload targeted browser cookies and session tokens.T1543.002 · Systemd ServiceThe payload installed a systemd service configured with Restart=always and RestartSec=30.T1552.001 · Credentials In FilesThe payload targeted credentials stored in files, including npm authentication tokens in ~/.npmrc.T1552.004 · Private KeysThe payload collected SSH private keys from developer machines.T1555.003 · Credentials from Web BrowsersThe payload targeted saved browser passwords and other browser credential material.T1567.002 · Exfiltration to Cloud StorageThe payload used POST /upload to the public file-sharing service temp.sh as a secondary exfiltration route.T1622 · Debugger EvasionThe payload checked for debuggers using PTRACE_ATTACH and PTRACE_SEIZE.
People
David RungeArch staff member who clarified the arojas commit forgery in the incident thread.Jonathan GrotelüschenArch staff member who posted the live affected-package list URL to the incident thread.KusonekoOpened the AUR-general incident thread on June 11, 2026, reporting malicious commits in alvr.Nicolas BoichatResearcher who used a local Gemma AI model via E2B to detect obfuscated Bun command patterns.
Malware
Products
Arch User RepositoryBetween 9 and 17 June 2026, someone adopted more than 1,900 orphaned packages in the Arch User Repository and wired them to pull a credential-stealing zombie payload.BunOrphaned packages referenced by other, non-orphaned packages would then force npm or bun to fetch the malicious atomic-lockfile package.npmA second, parallel npm campaign ran in the same window; this write-up covers Atomic Arch only.yayyay 13.0 shipped on June 17 with PKGBUILD age surfacing and hook-based filtering, giving users a better chance to spot suspicious recent updates before a package builds.
Tools
E2BResearcher Nicolas Boichat had to deploy a local Gemma AI model via E2B just to catch the obfuscated patterns.GemmaResearcher Nicolas Boichat had to deploy a local Gemma AI model via E2B just to catch the obfuscated patterns.snykMake sure you are using good tools like snyk to go over your codebase and a solid SIEM with good alerts to monitor the CI/CD process.