Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US Is Banning Foreign Robots—Even Roombas

    August 1, 2026

    Mamdani discount grocery store meme shows unrelated photo, false claim about family

    August 1, 2026

    Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief | Petrol prices

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US Is Banning Foreign Robots—Even Roombas
    • Mamdani discount grocery store meme shows unrelated photo, false claim about family
    • Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief | Petrol prices
    • What Worries Democrats as the Midterms Heat Up
    • Chinese AI Researchers Are Finding Their Voice on X
    • HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
    • Crypto Today: FTX Creditors Receive $900M Payout, Citadel Buys Situational Assets
    • What Homer’s ‘Odyssey’ Tells Us About the Economics of the Bronze Age
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Arch Linux disables AUR package adoption to stop malware flood

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 1, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.

    The decision was announced on the distribution’s mailing list by contributor Robin Candau, who said that the situation is temporary until a solution is found.

    “Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.

    image

    “We will send a follow-up once we’re able to. In the meantime, feel free to report suspicious adoption events or commits that haven’t been dealt with yet, and stay vigilant!”

    Independent Federated Intelligence Network (IFIN) conducted a technical analysis of the malware and reported that the campaign began on July 29 with the package ‘openconnect-sso.’

    IFIN reports that the campaign bears many similarities to the last campaign, including the use of the Tor network for staging.

    In June, a separate campaign hit AUR via more than 400 packages, distributing a Linux rootkit and info-stealer malware to unsuspecting users.

    In the latest attack, the researchers identified a two-stage infection, with the first stage acting as the loader, and the second one being a Linux x86_64 payload described as stealer malware with remote administration (RAT) and SSH worm features.

    Further analysis showed that the first-stage loader evades detection by checking for debuggers, sandboxes, virtual machines, and CI/CD environments before installing systemd services and cron jobs to ensure persistence.

    It then downloads and launches a Tor client disguised as dbus-daemon to retrieve the second-stage payload from an ‘.onion’ server.

    The second stage is a Rust-based infostealer that targets browser credentials, cryptocurrency wallets, password manager data, cloud and developer secrets, AI service API keys, SSH keys, and messaging platform tokens.

    It also provides the attacker with remote command execution over an encrypted Tor channel and can spread laterally by using stolen SSH keys to copy and execute itself on other systems.

    A Reddit user tracking the campaign alleges that it has expanded to over 200 AUR packages, either through compromised maintainer accounts or by adopting orphaned packages.

    According to the same researcher, the campaign has spread to fairly popular AUR packages such as boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server.

    The compromised status of these packages has not been independently confirmed, and a list of all 200 AUR packages believed to be malicious has not been made available as of publication.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    adoption Arch AUR disables flood Linux Malware package stop
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

    Amgen says cloud data breach exposed patient health, proprietary info

    CareCloud Data Breach Impacts Over 350,000

    EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

    Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

    OpenAI says its new GPT 5.6 models are becoming more cost-efficient

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US Is Banning Foreign Robots—Even Roombas

    August 1, 2026

    Mamdani discount grocery store meme shows unrelated photo, false claim about family

    August 1, 2026

    Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief | Petrol prices

    August 1, 2026

    What Worries Democrats as the Midterms Heat Up

    August 1, 2026
    Latest Posts

    New to Linux? This 10-day checklist will help you settle in nice and easy

    July 22, 2026

    Tories ask HMRC to investigate whether Nigel Farage owes tax on £5m gift | Nigel Farage

    July 22, 2026

    Greece derails EU’s Russia sanctions plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US Is Banning Foreign Robots—Even Roombas

    August 1, 2026

    Mamdani discount grocery store meme shows unrelated photo, false claim about family

    August 1, 2026

    Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief | Petrol prices

    August 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.