Hackers Injected Malicious Firefox Browser Packages to Arch Linux User Repository

Security researchers discovered that threat actors had uploaded three corrupted browser packages, firefox-patch-bin, librewolf-fix-bin, and zen-browser-patched-bin, to the Arch User Repository (AUR). A security advisory was issued, urging users to search for the infected packages via pacman -Q firefox-patch-bin and related names, uninstall them, and inspect /etc/systemd/system/rat-agent.service for removal. These packages appeared to be benign forks of popular Firefox-based browsers but secretly installed a Remote Access Trojan (RAT) by pulling and executing a script from a malicious GitHub repository. According to the advisory, The Arch Linux security team revoked the maintainer’s privileges and purged the malicious entries from the AUR by July 18 at 18:00 UTC+2. Security best practices such as verifying PGP signatures on AUR submissions, leveraging arch-audit for vulnerability scans, and confining AUR builds to isolated containers can mitigate future supply chain threats. Users who installed any of these packages are urged to verify integrity, rotate credentials, and perform forensic checks for indicators of compromise. Late on July 16 at approximately 20:00 UTC+2, the first of the three tainted packages, firefox-patch-bin, was uploaded under the maintainer handle dlagents to the AUR. Users who believe they installed any of the compromised packages should immediately remove them and audit their systems for the aforementioned persistence artifacts. Fake Firefox AUR packages downloaded and executed a Remote Access Trojan from GitHub.

This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 23 Jul 2025 10:35:10 +0000


Cyber News related to Hackers Injected Malicious Firefox Browser Packages to Arch Linux User Repository

CVE-2021-47341 - In the Linux kernel, the following vulnerability has been resolved: KVM: mmio: Fix use-after-free Read in kvm_vm_ioctl_unregister_coalesced_mmio BUG: KASAN: use-after-free in kvm_vm_ioctl_unregister_coalesced_mmio+0x7c/0x1ec ...
1 year ago Tenable.com
Arch Linux pulls AUR packages that installed Chaos RAT malware - Arch Linux has pulled three malicious packages uploaded to the Arch User Repository (AUR) were used to install the CHAOS remote access trojan (RAT) on Linux devices. The AUR is a repository where Arch Linux users can publish package build scripts ...
5 months ago Bleepingcomputer.com
CVE-2024-40953 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
Hackers Injected Malicious Firefox Browser Packages to Arch Linux User Repository - Security researchers discovered that threat actors had uploaded three corrupted browser packages, firefox-patch-bin, librewolf-fix-bin, and zen-browser-patched-bin, to the Arch User Repository (AUR). A security advisory was issued, urging users to ...
5 months ago Cybersecuritynews.com
CVE-2024-36886 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-46763 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-40954 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
5000+ Malicious Packages Found In The Wild To Compromise Windows Systems - These packages, detected from November 2024 onward, employ sophisticated techniques to evade traditional security measures while executing harmful actions that can lead to data theft, unauthorized access, and complete system compromise. Similarly, ...
9 months ago Cybersecuritynews.com
Vulnerability Summary for the Week of March 4, 2024 - Published 2024-03-06 CVSS Score not yet calculated Source & Patch Info CVE-2023-52584416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67 PrimaryVendor - ...
1 year ago Cisa.gov
Vulnerability Summary for the Week of March 11, 2024 - Published 2024-03-15 CVSS Score not yet calculated Source & Patch Info CVE-2021-47111416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67 PrimaryVendor - Product linux - linux Description In the ...
1 year ago Cisa.gov
Malicious PyPI packages targeting highly specific MacOS machines - As part of our software package supply chain security efforts, we continuously scan for malware in newly released PyPI and NPM packages. In this post, we describe a particularly interesting cluster of malicious packages that we've identified. In late ...
1 year ago Securitylabs.datadoghq.com
CVE-2024-53195 - In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Get rid of userspace_irqchip_in_use Improper use of userspace_irqchip_in_use led to syzbot hitting the following WARN_ON() in kvm_timer_update_irq(): WARNING: CPU: 0 PID: ...
1 year ago Tenable.com
3 PYPI Packages Caught Spreading Malware - Recent reports have highlighted the malicious spreading of malware via 3 specific Python Package Index (PyPI) packages. These 3 packages were identified and reported by Sonatype, a software supply chain security firm. ...
2 years ago Securityaffairs.com
CVE-2025-38117 - In the Linux kernel, the following vulnerability has been resolved: ...
5 months ago
CVE-2025-37780 - In the Linux kernel, the following vulnerability has been resolved: ...
7 months ago
CVE-2021-47092 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2022-48763 - In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Forcibly leave nested virt when SMM state is toggled Forcibly leave nested virtualization operation if userspace toggles SMM state via KVM_SET_VCPU_EVENTS or ...
1 year ago Tenable.com
CVE-2021-47230 - In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Immediately reset the MMU context when the SMM flag is cleared Immediately reset the MMU context when the vCPU's SMM flag is cleared so that the SMM flag in the MMU role is ...
1 year ago Tenable.com
CVE-2024-26626 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-56658 - In the Linux kernel, the following vulnerability has been resolved: net: defer final 'struct net' free in netns dismantle Ilya reported a slab-use-after-free in dst_destroy [1] Issue is in xfrm6_net_init() and xfrm4_net_init() : They copy ...
1 year ago Tenable.com
CVE-2022-50661 - In the Linux kernel, the following vulnerability has been resolved: ...
2 weeks ago
116 Malicious PyPI Packages Downloaded Over 10,000 Times - A cluster of malicious Python projects has been identified in PyPI, the official Python PyPI package repository, which targets both Windows and Linux systems and often deploys a custom backdoor. In certain instances, the ultimate payload consists of ...
2 years ago Cybersecuritynews.com
CVE-2024-42270 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
Trouble in Da Hood: Malicious Actors Use Infected PyPI Packages to Target Roblox Cheaters | Imperva - In recent research on compromised and malicious PyPI packages, Imperva Threat Research has identified an ongoing malware campaign specifically targeting Roblox hackers. Over time, vast communities have assembled on various platforms such as Reddit, ...
1 year ago Imperva.com
CVE-2025-37957 - In the Linux kernel, the following vulnerability has been resolved: ...
7 months ago