More than 400 packages in the Arch User Repository (AUR) are distributing a Linux rootkit and infostealer malware targeting credentials and access tokens.

More than 400 packages in the Arch User Repository (AUR) are distributing a Linux rootkit and infostealer malware targeting credentials and access tokens.

Attackers hijacked 400+ Arch Linux AUR packages to run a Rust credential stealer, with optional eBPF rootkit support on root systems.

Dia 11 de junho de 2026 (ontem), um atacante assumiu o controle de mais de 400 pacotes do Arch User...

Arch Linux Supply Chain Malware, repo-slopscore & AI Model Security Concerns ...

Una vasta campagna malware ha colpito l'AUR di Arch Linux compromettendo centinaia di pacchetti e rubando credenziali.

Community repo freezes new accounts after attackers swamp it with poisoned package updates