ended6월 13일· 1 sources
Atomic Arch: Supply Chain Attack Compromises 400+ Arch Linux Packages
Arch Linux 공급망 침해, AUR 400개 패키지 악성코드 감염
Why it matters
Over 400 packages in Arch Linux's community repository (AUR) were hijacked to distribute sophisticated infostealer malware with eBPF rootkit capabilities. The attack demonstrates critical vulnerabilities in community-driven package ecosystems where abandoned packages can be easily claimed and weaponized. When executed with root privileges, the malware deploys a kernel-level rootkit designed to persist beyond standard removal attempts, making complete system reinstallation necessary for reliable recovery.
1
Sources
+0
24h
—
Growth
100d
Active
AURsupply chaininfostealereBPF rootkitcredential theft