Over 400 Arch Linux packages compromised to push rootkit, infostealer
More than 400 packages in the Arch User Repository (AUR) are distributing malware targeting credentials and access tokens.
Intelligence analysis by Qwen 2.5 (3B)

Malware is being pushed through compromised packages in the popular Arch Linux AUR repository, potentially compromising user data.
Some people who make software for a Linux system called Arch Linux put bad stuff in their programs that can steal passwords and hide itself inside your computer. This is like if someone put a sneaky toy in your lunchbox that could tell you where all the cookies are kept, but it also might be able to open doors without asking.
Analysis
Background on Arch Linux and AUR
Arch Linux is a popular distribution for power users and developers. The AUR serves as an essential repository for the latest versions of software not available in the official repositories.
Compromise Details
Independent Federated Intelligence Network (IFIN) reported that over 400 packages are distributing a rootkit and infostealer malware through preinstall scripts. These scripts download and execute a malicious npm package called atomic-lockfile, which includes a Linux ELF payload designed for developer workstations.
Analysis of the Malware
The atomic-lockfile payload contains a credential stealer with optional eBPF rootkit capabilities. It targets sensitive data such as browser cookies, Slack, Microsoft Teams, GitHub credentials, and SSH artifacts. The malware can hide processes, files, and network interfaces within the kernel.
Detection and Response
Sonatype also reported on this campaign targeting AUR. They identified 20 orphaned packages that were hijacked to push atomic-lockfile. Arch Linux maintainers are working to identify and remove all malicious commits, and ban the accounts pushing them.
Recommendations for Users
Users should review the list of affected packages and look for indicators of compromise provided in the report from Whanos. If compromised packages are found, users should rotate their credentials and consider reinstalling Arch from scratch.
Key points
- Over 400 packages in AUR are compromised with malicious software
- The malware targets sensitive user information such as passwords and access tokens
- Arch Linux users should review the list of affected packages for indicators of compromise
- AUR maintainers are working to remove all malicious commits and ban accounts pushing them
- Users should rotate their credentials and consider reinstalling Arch from scratch if they find compromised packages
By working together, Arch Linux maintainers and users can identify and remove these malicious packages before they cause any real damage. This will help keep everyone's computers safe from this kind of sneaky bad software.
If not caught quickly, the malware could spread to more people’s computers, making it harder for them to know what is happening on their systems and potentially leading to even bigger problems like data theft or system crashes.



