InFeeo
Global
technology-news
New
Language

Channels

AUR Packages Compromised with Infostealer and Rootkit(lists.archlinux.org)
Last Updated: 2026-06-12T04:22:42Z (UTC) What’s Happening It appears a new AUR package maintainer (arojas) adopted and infected 408+ packages. The compromise was reported and other AUR maintainers have been working to remove the infected packages. The affected packages were modified with preinstall scripts to use npm to install the atomic-lockfile package, a malicious payload. Here’s an example of the change: This blog has a deep dive into the attack. Actions If you don’t use Arch (b...
AUR Report Thread(hyperkitty.readthedocs.org)
Jonathan Grotelüschen 11 Jun 2026 11 Jun '26 17:47 Hi everyone, we’re working hard to reset/delete all malicious commits and ban the accounts. If you find more malicious packages, please **send them as a reply to this email** to keep them all in one thread. Thanks! -- tippfehlr Attachments: OpenPGP_signature.asc (application/pgp-signature — 228 Bytes) Show replies by date