[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-thousands-of-arch-aur-packages-found-with-hidden-malware":10,"sections":36},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":24,"persona_id":22,"persona_name":22,"section":25,"tags":26,"sources":31,"feedback":35,"feedback_at":22,"cost_usd":35,"total_tokens":35},770,"thousands-of-arch-aur-packages-found-with-hidden-malware","400 AUR Packages Found Carrying Infostealer and Rootkit","Roughly 400 community-submitted Arch Linux packages were compromised with credential-harvesting and persistence malware.","Around 400 packages in the Arch User Repository were found carrying infostealer and rootkit malware.\n\nThe Arch User Repository is a community-maintained collection of user-submitted software packages — officially unsupported by the Arch Linux project and explicitly unreviewed. Roughly 400 of those packages were found to contain two distinct malicious payloads: an infostealer designed to harvest credentials and sensitive data from the host system, and a rootkit that hides its presence and can survive reboots. The scale suggests a deliberate effort to compromise packages with meaningful install counts rather than a scattered, opportunistic attack.\n\nAUR is one of the most actively used supplementary repositories in the Linux ecosystem. Many Arch users pull from it routinely — for software absent from the official repos, for newer package versions, or simply out of habit. A poisoned package delivered through a normal install or update workflow, combined with a rootkit working to stay hidden, is exactly the kind of compound threat that turns a one-time compromise into a prolonged breach. Credential theft plus persistent access is the post-exploitation recipe.\n\nSupply chain attacks on package repositories are now a recurring story. The xz utils backdoor demonstrated how far a patient attacker can get inside trusted infrastructure — but AUR never had a strong trust model to begin with. The project has always told users to audit what they install. At 400 packages, that warning is looking less like prudent advice and more like a liability disclaimer that nobody reads.","[\"arch-linux\",\"supply-chain\",\"malware\",\"rootkit\"]","2026-06-12T05:59:39.000Z","2026-06-12T10:59:21.140Z","2026-06-18T11:45:35.491Z","published",null,[],"https:\u002F\u002Fcdn.xyz.onl\u002Farticle-images\u002Fthousands-of-arch-aur-packages-found-with-hidden-malware.webp","security",[27,28,29,30],"arch-linux","supply-chain","malware","rootkit",[32],{"name":33,"url":34},"Hacker News","https:\u002F\u002Fdiscourse.ifin.network\u002Ft\u002F400-aur-packages-compromised-with-infostealer-and-rootkit\u002F577",0,{"sections":37},[38,43,47,52,57,62,67,72,77,82,87,92,97,102],{"name":39,"slug":40,"count":41,"latest_published_at":42},"AI","ai",2602,"2026-07-18T18:30:00.000Z",{"name":44,"slug":25,"count":45,"latest_published_at":46},"Security",315,"2026-07-17T19:30:00.000Z",{"name":48,"slug":49,"count":50,"latest_published_at":51},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":56},"Policy","policy",169,"2026-07-17T19:49:53.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Hardware","hardware",126,"2026-07-16T20:09:48.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Consumer Tech","consumer-tech",94,"2026-07-16T16:29:46.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Software","software",72,"2026-07-17T09:42:05.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Science","science",66,"2026-07-10T10:29:37.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Dev Tools","dev-tools",60,"2026-07-16T16:59:13.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Startups","startups",42,"2026-07-16T16:30:35.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"General","general",29,"2026-07-10T22:28:58.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]