malware
Over 400 Arch Linux packages compromised to push rootkit, infostealer
High
Summary
Over 400 Arch Linux packages within the AUR repository have been compromised, distributing a Linux rootkit and infostealer malware designed to steal developer credentials and access tokens. The attack involved a malicious npm package, atomic-lockfile, which included an eBPF rootkit and targeted various developer tools and services. This highlights the risks associated with community-maintained repositories and the importance of vigilance for Arch Linux users.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data