Arch Linux disables AUR package adoption to stop malware flood

1 hour ago 6

Arch Linux disables AUR package adoption to stop malware flood

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.

The decision was announced on the distribution's mailing list by contributor Robin Candau, who said that the situation is temporary until a solution is found.

“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.

image

“We will send a follow-up once we're able to. In the meantime, feel free to report suspicious adoption events or commits that haven't been dealt with yet, and stay vigilant!”

Independent Federated Intelligence Network (IFIN) conducted a technical analysis of the malware and reported that the campaign began on July 29 with the package ‘openconnect-sso.’

IFIN reports that the campaign bears many similarities to the last campaign, including the use of the Tor network for staging.

In June, a separate campaign hit AUR via more than 400 packages, distributing a Linux rootkit and info-stealer malware to unsuspecting users.

In the latest attack, the researchers identified a two-stage infection, with the first stage acting as the loader, and the second one being a Linux x86_64 payload described as stealer malware with remote administration (RAT) and SSH worm features.

Further analysis showed that the first-stage loader evades detection by checking for debuggers, sandboxes, virtual machines, and CI/CD environments before installing systemd services and cron jobs to ensure persistence.

It then downloads and launches a Tor client disguised as dbus-daemon to retrieve the second-stage payload from an ‘.onion’ server.

The second stage is a Rust-based infostealer that targets browser credentials, cryptocurrency wallets, password manager data, cloud and developer secrets, AI service API keys, SSH keys, and messaging platform tokens.

It also provides the attacker with remote command execution over an encrypted Tor channel and can spread laterally by using stolen SSH keys to copy and execute itself on other systems.

A Reddit user tracking the campaign alleges that it has expanded to over 200 AUR packages, either through compromised maintainer accounts or by adopting orphaned packages.

According to the same researcher, the campaign has spread to fairly popular AUR packages such as boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server.

The compromised status of these packages has not been independently confirmed, and a list of all 200 AUR packages believed to be malicious has not been made available as of publication.

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Read Entire Article