Product
Arch User Repository
- First Reported
- Jul 21, 2026
- Latest Reported
- Jul 21, 2026
Reported Context (1)
- Between 9 and 17 June 2026, someone adopted more than 1,900 orphaned packages in the Arch User Repository and wired them to pull a credential-stealing zombie payload. Atomic Arch Campaign Used Compromised AUR Packages to Deliver an Infostealer
Malware (3)
People (4)
MITRE ATT&CK (12)
Products (3)
Tools (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.