CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Atomic Arch: Supply Chain Attack on Arch Linux AUR

June 25, 2026

A campaign tracked by Sonatype as Atomic Arch (Sonatype-2026-003775) hijacked over 400 AUR packages to deploy a Rust-based credential stealer and optional eBPF rootkit. The attack targeted orphaned packages and used malicious npm packages to deliver payloads.