400+ Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Over 400 packages in the Arch User Repository (AUR) were hijacked, leading to a credential stealer deployment. The attack targets trust model rather than software flaws.
Intelligence analysis by Qwen 2.5 (3B)

Attackers took over more than 400 AUR packages and rewrote build scripts to install a Rust binary that steals developer secrets and hides itself with an eBPF rootkit.
Bad guys took over some software packages in a Linux system and changed them so they can steal passwords and hide themselves. Now people need to look carefully at the packages they use and change their passwords if needed.
Analysis
Attack Details
The attackers adopted abandoned packages from the Arch User Repository (AUR) and edited their build files to install a Rust binary that acts as a credential stealer. The binary collects various types of data including cookies, tokens, session data, and SSH keys. It also installs an eBPF rootkit for persistence.
Impact and Detection
The attack was detected when users reported suspicious AUR package installations. Arch maintainers are resetting the malicious commits, banning accounts, and asking users to report suspect packages. Users should check their systems for any compromised credentials and rotate sensitive information.
Key points
- Over 400 AUR packages were hijacked
- The attack targets trust model rather than software flaws
- Users should check for suspicious package installations and rotate sensitive information
- Arch maintainers are taking steps to clean up the affected packages
The Arch maintainers are taking steps to clean up the affected packages and prevent future attacks, which will help protect users from similar threats in the future.
If attackers find new ways to hide or bypass detection, this type of attack could become more common. Users need to stay vigilant and keep their systems updated with security patches.



