惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
U
Unit 42
MyScale Blog
MyScale Blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
量子位
IT之家
IT之家
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
Recent Announcements
Recent Announcements
V
Visual Studio Blog
G
Google Developers Blog
Last Week in AI
Last Week in AI
雷峰网
雷峰网
博客园 - 聂微东
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
博客园 - 司徒正美
Y
Y Combinator Blog
T
The Blog of Author Tim Ferriss
月光博客
月光博客
aimingoo的专栏
aimingoo的专栏

Truesec

The Ryde Data Breach - Truesec CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223) Securing IT, OT, and IoT When the Digital Meets the Physical
Supply Chain Attack Compromising Arch Linux AUR Packages ...
Hjalmar Desmond · 2026-06-16 · via Truesec

A large-scale supply chain attack targeting the Arch User Repository (AUR) has resulted in the compromise of over 1,500 community-maintained packages[2]. Reportedly, attackers injected malicious build scripts to deploy a Rust-based infostealer and an optional eBPF rootkit on affected systems, primarily targeting developer environments and CI/CD infrastructure [1].

The attackers injected commands into build scripts that pulled malicious dependencies, including rogue npm packages such as atomic-lockfile and js-digest, which executed automatically during the package build process. This approach allowed attackers to distribute malware without modifying the software itself, instead abusing the trusted build pipeline [1].

The payload included[1]:
A Rust-based infostealer designed to collect sensitive data such as:

  • Browser cookies and session data
  • SSH keys and shell histories
  • API tokens (e.g., GitHub, npm, and cloud services)
  • Credentials from collaboration tools like Slack, Discord, and Teams
  • An eBPF rootkit that can load when executed with elevated privileges, enabling stealth by hiding processes and artifacts at the kernel level

The AUR is Arch Linux’s community package collection, and it is separate from the official Arch repositories, which were not affected.

Affected Products

Arch Linux AUR
A list of affected packages at the time of writing can be found here[2]:
https://md.archlinux.org/s/SxbqukK6IA

The list of affected packages is extensive and evolving. Customers should treat any AUR package installed or updated since June 11, 2026 as potentially compromised.
Exploitation

The campaign began on or around June 11, 2026, and actively compromised hundreds of AUR packages, later expanding to over 1,500 affected packages.
Recommended Actions

  • Review all AUR packages installed or updated since June 11, 2026, and compare them against known affected package lists found here: https://md.archlinux.org/s/SxbqukK6IA
  • Immediately rotate all credentials (SSH keys, API tokens, passwords) on systems that may have installed affected packages
  • Treat systems where malicious packages were executed with elevated privileges as potentially fully compromised and consider reinstallation from trusted media
  • Monitor for suspicious activity, including:
    • Unusual outbound connections (e.g., HTTP exfiltration or Tor usage)
    • Unexpected systemd services or persistence mechanisms

Limit reliance on unvetted third-party repositories and implement stricter validation of build scripts before execution.

References

[1] https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
[2] https://md.archlinux.org/s/SxbqukK6IA
[3] https://archlinux.org/news/active-aur-malicious-packages-incident/

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights