ended6월 14일· 1 sources
AUR 패키지가 정보 탈취기와 루트킷에 감염됨
Why it matters
This incident represents a sophisticated supply chain attack combining data exfiltration with eBPF rootkits—a rare and severe combination. Compromising 400+ AUR packages through maintainer impersonation, it exposes critical vulnerabilities in community-driven repositories where anyone can adopt abandoned packages. The attack highlights the fundamental tension between open-source accessibility and security in package management systems.
1
Sources
+0
24h
—
Growth
99d
Active
AURsupply chain attackeBPF rootkitnpmArch Linuximpersonation