| Rich Mingin (PLUG) via plug on 15 Jun 2026 11:03:20 -0700 |
[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]
| Re: [PLUG] Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit |
I mean, I'm sure this will be preaching to the choir for most folks on the list, but some points to keep in mind: 1. If you are new to Arch, you should not have installed anything from the AUR. There is nothing in the AUR that you should need for basic functionality of your system. 2. If you have been using Arch, you should be keeping the number of AUR packages to a minimum, for reasons including security and maintenance overhead. This feeds into #3: 3. You are responsible for reviewing all updates to all your install AUR packages. If you are unable or unwilling to notice the addition of [footnote 1] to a package you are using, should you be using that package? You have outsourced your system security to literally a random stranger. This is an ideal time for anyone reading this and running an arch derivative to review all their installed AUR packages, and verify them. If you are infected, it's too late, burn the install down, format disks, start again, but if you are not infected now, maybe it's a great time to reduce your attackable surface by jettisoning anything from the AUR that you don't recall installing or using? I see far too many packages being "carried" and updated on autopilot. That's the real core issue here. If it breaks something you *do* need/use, you have to make the call between losing the AUR dependency and committing to reviewing and maintaining it on your systems, but if you're not using it, why have it installed? The package manager is quite good at spotting impacts, removing AUR packages shouldn't break things unexpectedly. footnote 1, example of changes to an AUR package in the first wave. The changes should be pretty obviously unneeded and obscured. https://aur.archlinux.org/cgit/aur.git/commit/?h=oracle-bin&id=eceeb808ef933a66285ea68cefd72c1b5f4374c9 On Mon, Jun 15, 2026 at 1:50 PM jeffv via plug <plug@lists.phillylinux.org> wrote: > > Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF > Rootkit > > https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html > > Attackers took over more than 400 packages in the Arch User Repository > (AUR) this week and rewrote their build scripts to install a credential > stealer on any machine that built them. > > The malware is a Rust binary built to harvest developer secrets. When it > lands with root, it can also load an eBPF rootkit to hide itself. The > AUR is Arch Linux's community package collection, and it is separate > from the official Arch repositories, which were not affected. > ___________________________________________________________________________ > Philadelphia Linux Users Group -- http://www.phillylinux.org > Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce > General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug ___________________________________________________________________________ Philadelphia Linux Users Group -- http://www.phillylinux.org Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug