Rich Mingin (PLUG) via plug on 15 Jun 2026 11:03:20 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit


I mean, I'm sure this will be preaching to the choir for most folks on
the list, but some points to keep in mind:

1. If you are new to Arch, you should not have installed anything from
the AUR. There is nothing in the AUR that you should need for basic
functionality of your system.

2. If you have been using Arch, you should be keeping the number of
AUR packages to a minimum, for reasons including security and
maintenance overhead. This feeds into #3:

3. You are responsible for reviewing all updates to all your install
AUR packages. If you are unable or unwilling to notice the addition of
[footnote 1] to a package you are using, should you be using that
package? You have outsourced your system security to literally a
random stranger.

This is an ideal time for anyone reading this and running an arch
derivative to review all their installed AUR packages, and verify
them. If you are infected, it's too late, burn the install down,
format disks, start again, but if you are not infected now, maybe it's
a great time to reduce your attackable surface by jettisoning anything
from the AUR that you don't recall installing or using? I see far too
many packages being "carried" and updated on autopilot. That's the
real core issue here. If it breaks something you *do* need/use, you
have to make the call between losing the AUR dependency and committing
to reviewing and maintaining it on your systems, but if you're not
using it, why have it installed? The package manager is quite good at
spotting impacts, removing AUR packages shouldn't break things
unexpectedly.

footnote 1, example of changes to an AUR package in the first wave.
The changes should be pretty obviously unneeded and obscured.
https://aur.archlinux.org/cgit/aur.git/commit/?h=oracle-bin&id=eceeb808ef933a66285ea68cefd72c1b5f4374c9

On Mon, Jun 15, 2026 at 1:50 PM jeffv via plug
<plug@lists.phillylinux.org> wrote:
>
> Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF
> Rootkit
>
> https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
>
> Attackers took over more than 400 packages in the Arch User Repository
> (AUR) this week and rewrote their build scripts to install a credential
> stealer on any machine that built them.
>
> The malware is a Rust binary built to harvest developer secrets. When it
> lands with root, it can also load an eBPF rootkit to hide itself. The
> AUR is Arch Linux's community package collection, and it is separate
> from the official Arch repositories, which were not affected.
> ___________________________________________________________________________
> Philadelphia Linux Users Group         --        http://www.phillylinux.org
> Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
> General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug