news.mlab.sh
Back to the feed
malware

Over 400 Arch Linux packages compromised to push rootkit, infostealer

High
Summary

Over 400 Arch Linux packages within the AUR repository have been compromised, distributing a Linux rootkit and infostealer malware designed to steal developer credentials and access tokens. The attack involved a malicious npm package, atomic-lockfile, which included an eBPF rootkit and targeted various developer tools and services. This highlights the risks associated with community-maintained repositories and the importance of vigilance for Arch Linux users.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.