AUR malware attack?

Discussion in 'Linux' started by ILikeTechnology, Jun 15, 2026.

  1. ILikeTechnology

    ILikeTechnology MDL Junior Member

    Mar 24, 2026
    50
    47
    0
    Recently heard that on June 11th, the AUR got attacked by this malware, dubbed "Atomic Arch"

    Apparently it uses orphaned AUR packages to inject an NPM install snippet to install their own rootkit/credential harvesting JS, using npm install atomic-lockfile minimist chalk and a dependency [email protected].

    I use EndeavourOS, any other Linux users that happen to use an Arch-based distro? I haven't really been on Linux for the past four days, so I am not gonna update for a while and stick to my Windows dualboot for nowo_O It is also rootkit-like in the terms of behavior and persistence and has infected around 1,500 packages

    Hope everyone stays safe!
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. hoak

    hoak MDL Addicted

    Nov 13, 2009
    687
    1,937
    30
  3. ILikeTechnology

    ILikeTechnology MDL Junior Member

    Mar 24, 2026
    50
    47
    0
    So far I'm safe. checked and no signs of the malware :D the only time I'm updating is when it all fades out and the AUR team actually cleans this whole mess up. I don't even have npm installed so the rootkit cannot install itself anyway
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...