惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
博客园_首页
美团技术团队
M
MIT News - Artificial intelligence
人人都是产品经理
人人都是产品经理
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
J
Java Code Geeks
T
Tailwind CSS Blog
Jina AI
Jina AI
量子位
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
爱范儿
爱范儿
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
宝玉的分享
宝玉的分享
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
博客园 - 三生石上(FineUI控件)
L
LangChain Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
博客园 - Franky
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Truesec

CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223) Securing IT, OT, and IoT When the Digital Meets the Physical Russia Rolls Out Surveillance Through State-Backed “Super App” MAX
Supply Chain Attack Compromising Arch Linux AUR Packages ...
Hjalmar Desmond · 2026-06-16 · via Truesec

A large-scale supply chain attack targeting the Arch User Repository (AUR) has resulted in the compromise of over 1,500 community-maintained packages[2]. Reportedly, attackers injected malicious build scripts to deploy a Rust-based infostealer and an optional eBPF rootkit on affected systems, primarily targeting developer environments and CI/CD infrastructure [1].

The attackers injected commands into build scripts that pulled malicious dependencies, including rogue npm packages such as atomic-lockfile and js-digest, which executed automatically during the package build process. This approach allowed attackers to distribute malware without modifying the software itself, instead abusing the trusted build pipeline [1].

The payload included[1]:
A Rust-based infostealer designed to collect sensitive data such as:

  • Browser cookies and session data
  • SSH keys and shell histories
  • API tokens (e.g., GitHub, npm, and cloud services)
  • Credentials from collaboration tools like Slack, Discord, and Teams
  • An eBPF rootkit that can load when executed with elevated privileges, enabling stealth by hiding processes and artifacts at the kernel level

The AUR is Arch Linux’s community package collection, and it is separate from the official Arch repositories, which were not affected.

Affected Products

Arch Linux AUR
A list of affected packages at the time of writing can be found here[2]:
https://md.archlinux.org/s/SxbqukK6IA

The list of affected packages is extensive and evolving. Customers should treat any AUR package installed or updated since June 11, 2026 as potentially compromised.
Exploitation

The campaign began on or around June 11, 2026, and actively compromised hundreds of AUR packages, later expanding to over 1,500 affected packages.
Recommended Actions

  • Review all AUR packages installed or updated since June 11, 2026, and compare them against known affected package lists found here: https://md.archlinux.org/s/SxbqukK6IA
  • Immediately rotate all credentials (SSH keys, API tokens, passwords) on systems that may have installed affected packages
  • Treat systems where malicious packages were executed with elevated privileges as potentially fully compromised and consider reinstallation from trusted media
  • Monitor for suspicious activity, including:
    • Unusual outbound connections (e.g., HTTP exfiltration or Tor usage)
    • Unexpected systemd services or persistence mechanisms

Limit reliance on unvetted third-party repositories and implement stricter validation of build scripts before execution.

References

[1] https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
[2] https://md.archlinux.org/s/SxbqukK6IA
[3] https://archlinux.org/news/active-aur-malicious-packages-incident/

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights