Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a Rust-based credential stealer and an optional eBPF rootkit. The campaign, tracked by Sonatype as Atomic Arch (Sonatype-2026-003775, CVSS 8.7), targeted developer workstations and build systems. The malicious payload, delivered via the npm package atomic-lockfile@1.4.2, collects browser cookies, tokens, SSH keys, and cloud credentials, exfiltrating data over HTTP to temp.sh and using a Tor onion service for C2. With root privileges, it can load an eBPF rootkit that hides processes and socket inodes. A second wave used bun install js-digest with a separate malicious binary. Arch maintainers are resetting commits and banning accounts, but the affected list remains incomplete. Users who installed or updated AUR packages on or after June 11 should check against community lists, rotate compromised credentials, and inspect for persistence mechanisms. If the payload ran as root, reinstallation from trusted media is recommended.
CVEs: CVE-2026-11645
Malware: Atomic Arch, deps, atomic-lockfile, js-digest
Companies: Sonatype, Arch Linux, Socket
Products: Chrome, Edge, Brave, Slack, Discord, Microsoft Teams, GitHub, npm, HashiCorp Vault, OpenAI, ChatGPT, Docker
Original source: thehackernews.com