Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Arch Linux disables AUR package adoption to stop malware flood

    July 31, 2026

    Amgen says cloud data breach exposed patient health, proprietary info

    July 31, 2026

    OpenAI says its new GPT 5.6 models are becoming more cost-efficient

    July 31, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Arch Linux disables AUR package adoption to stop malware flood
    News

    Arch Linux disables AUR package adoption to stop malware flood

    adminBy adminJuly 31, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Arch Linux disables AUR package adoption to stop malware flood

    The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.

    The decision was announced on the distribution’s mailing list by contributor Robin Candau, who said that the situation is temporary until a solution is found.

    “Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.

    image

    “We will send a follow-up once we’re able to. In the meantime, feel free to report suspicious adoption events or commits that haven’t been dealt with yet, and stay vigilant!”

    Independent Federated Intelligence Network (IFIN) conducted a technical analysis of the malware and reported that the campaign began on July 29 with the package ‘openconnect-sso.’

    IFIN reports that the campaign bears many similarities to the last campaign, including the use of the Tor network for staging.

    In June, a separate campaign hit AUR via more than 400 packages, distributing a Linux rootkit and info-stealer malware to unsuspecting users.

    In the latest attack, the researchers identified a two-stage infection, with the first stage acting as the loader, and the second one being a Linux x86_64 payload described as stealer malware with remote administration (RAT) and SSH worm features.

    Further analysis showed that the first-stage loader evades detection by checking for debuggers, sandboxes, virtual machines, and CI/CD environments before installing systemd services and cron jobs to ensure persistence.

    It then downloads and launches a Tor client disguised as dbus-daemon to retrieve the second-stage payload from an ‘.onion’ server.

    The second stage is a Rust-based infostealer that targets browser credentials, cryptocurrency wallets, password manager data, cloud and developer secrets, AI service API keys, SSH keys, and messaging platform tokens.

    It also provides the attacker with remote command execution over an encrypted Tor channel and can spread laterally by using stolen SSH keys to copy and execute itself on other systems.

    A Reddit user tracking the campaign alleges that it has expanded to over 200 AUR packages, either through compromised maintainer accounts or by adopting orphaned packages.

    According to the same researcher, the campaign has spread to fairly popular AUR packages such as boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server.

    The compromised status of these packages has not been independently confirmed, and a list of all 200 AUR packages believed to be malicious has not been made available as of publication.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAmgen says cloud data breach exposed patient health, proprietary info
    admin
    • Website

    Related Posts

    News

    Amgen says cloud data breach exposed patient health, proprietary info

    July 31, 2026
    News

    OpenAI says its new GPT 5.6 models are becoming more cost-efficient

    July 31, 2026
    News

    Infosec News Nuggets — July 31, 2026 – AboutDFIR

    July 31, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    Arch Linux disables AUR package adoption to stop malware flood

    July 31, 2026

    Amgen says cloud data breach exposed patient health, proprietary info

    July 31, 2026

    OpenAI says its new GPT 5.6 models are becoming more cost-efficient

    July 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.