malware Over 400 Arch Linux packages compromised to push rootkit, infostealer Over 400 Arch Linux packages within the AUR repository have been compromised, distributing a Linux rootkit and infostealer malware designed to steal developer credentials and access tokens. The attack involved a malicious npm package, atomic-lockfile, which included an eBPF rootkit and targeted various developer tools… BleepingComputer · Jun 12, 2026 High USrootkitinfostealeraur