By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Attackers compromised over 400 packages within the Arch User Repository (AUR) this week, altering their build scripts to deploy a credential-stealing malware on affected systems. The malicious payload, a Rust binary, is designed to exfiltrate developer secrets. Upon gaining root privileges, the malware can also install an eBPF rootkit to conceal its presence. The AUR serves as Arch Linux's community-driven package repository and operates independently from the official Arch Linux repositories. This incident highlights a significant security breach within a widely used community software source. The compromised packages were identified and removed by Arch Linux maintainers, who are investigating the full extent of the attack and its potential impact on users who may have unknowingly built or installed the affected packages. Users are advised to review their installed packages and system logs for any suspicious activity.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.