Threat reportSupply ChainTL-2026-0782
"Atomic Arch" AUR Supply-Chain Attack: 400+ Orphaned Arch User Repository Packages Backdoored via Malicious npm Dependencies (atomic-lockfile / js-digest) Deploying a Linux Infostealer with eBPF Rootkit
"Atomic Arch" AUR Supply-Chain Attack (TL-2026-0782), also tracked as Atomic Arch, is a high-severity supply-chain compromise, first published 2026-06-12. It has no confirmed attribution, affects Arch User Repository (AUR) User-contributed AUR packages, maps to 25 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 29 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-0782
- Threat ID
- TL-2026-0782
- Also known as
- Atomic Arch, Sonatype-2026-003775
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, open-source, cryptocurrency
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 29
How "Atomic Arch" AUR Supply-Chain Attack works
Threat actors hijacked 400+ orphaned Arch User Repository (AUR) packages — partly by forging git commits to impersonate KDE maintainer 'arojas' — and modified their PKGBUILD/.install hooks to silently pull malicious npm/bun packages (atomic-lockfile, js-digest). The packages dropped a multi-stage Linux ELF infostealer ('deps') that exfiltrates browser credentials, SSH keys, cloud/dev tokens and crypto-wallet data to a Tor onion C2, with optional root-only eBPF rootkit process/file/socket hiding. Official Arch binary repositories were unaffected.
Between June 9 and June 12, 2026 a coordinated supply-chain campaign — dubbed "Atomic Arch" by Sonatype — abused the open ownership-claim and contribution model of the Arch User Repository (AUR). The AUR is a community-driven repository of user-submitted PKGBUILD build recipes that AUR helpers such as `yay` and `paru` execute on the end-user's machine; it is explicitly outside Arch Linux's signed binary repositories. Attackers targeted orphaned-but-trusted packages with existing install bases to maximize reach while minimizing scrutiny.
For a portion of the campaign the attackers forged git commit authorship to impersonate legitimate KDE/Arch maintainer 'arojas' (Antonio Rojas), who Arch developer David Runge clarified was NOT a malicious maintainer but an impersonation victim. Additional attacker-controlled AUR accounts (custodiatovar, veramagalhaes) pushed a secondary wave using the bun package manager and the js-digest package. The malicious npm/bun packages were published under accounts including 'herbsobering' and 'krisztinavarga'.
The poisoned PKGBUILDs added a post-install/.install/.hook step running `npm install atomic-lockfile minimist chalk` (and a parallel `bun install js-digest` wave). atomic-lockfile v1.4.2 carried a `"preinstall": "./src/hooks/deps"` lifecycle hook pointing at a bundled 3,040,376-byte x86-64 PIE ELF (SHA256 6144D433F8A0316869877B5F834C801251BBB936E5F1577C5680878C7443C98B). On execution the stealer harvests Chromium-family browser cookies/credentials (Chrome, Edge, Brave, Vivaldi, Opera), Firefox profiles, SSH private keys, shell histories (.bash_history/.zsh_history/fish_history), GitHub/npm/Slack/Discord/Microsoft Teams/Telegram tokens, HashiCorp Vault tokens, Docker/Podman credentials, VPN (.ovpn) profiles, /etc/machine-id, and cryptocurrency wallet data (including Monero monero-wallet-gui artifacts) and seed phrases. It validates harvested tokens against api.openai.com, api.github.com, registry.npmjs.org, discord.com and teams.microsoft.com.
A decoded 62-byte ciphertext at offset 0x2DA96, deobfuscated with a 32-byte repeating XOR key at 0x1AA60, yields the primary C2 onion host olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion. The stealer beacons via `POST /api/agent HTTP/1.0` over TCP/80 and TCP/8080 using a SOCKS-style local transport on 127.0.0.1, stages a secondary Linux binary from <onion>/bin/linux (verified against <onion>/bin/sha256/linux, reference hash 47893d9badc38c54b71321263ce8178c1abb10396e0aadf9793e61ec8829e204), and exfiltrates collected archives to the public temp.sh service via `POST /upload HTTP/1.1`. Persistence is via systemd: root installs copy the binary to /var/lib/ with a unit under /etc/systemd/system/, while non-root installs use ~/.config/systemd/user/, both with Restart=always / RestartSec=30, using /proc/self/exe and flock() for single-instance control. When running as root (geteuid()==0 with CAP_BPF / CAP_SYS_ADMIN) the malware loads an eBPF program (scales.bpf.c) that hooks getdents64() and pins maps at /sys/fs/bpf/hidden_pids, /sys/fs/bpf/hidden_names and /sys/fs/bpf/hidden_inodes to hide its PIDs, process names and socket inodes from /proc, ps and htop, and kills attempted ptrace attachments. Sonatype tracks the malicious dependency as Sonatype-2026-003775 (vendor CVSS 8.7). No CVE was assigned (an abuse-of-trust supply-chain compromise rather than a software vulnerability). Arch maintainers ran a large-scale deletion campaign removing malicious updates and blocking attacker accounts; official Arch repositories were never affected.
MITRE ATT&CK techniques used in TL-2026-0782
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Defense Evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1036 Masquerading; T1564 Hide Artifacts; T1622 Debugger Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery
Initial Access
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Persistence
T1543 Create or Modify System Process
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Affected products and versions in "Atomic Arch" AUR Supply-Chain Attack
- Arch User Repository (AUR) — User-contributed AUR packages (orphaned/adopted)
Vulnerable versions: 400+ packages modified 2026-06-09 to 2026-06-12, e.g. alvr, guiscrcpy, netmon-git, inadyn-mt, nodejs-elm, keepassx2, premake-git
Fixed in: Malicious updates removed by Arch maintainers; rebuild from clean PKGBUILD - npm Registry — atomic-lockfile
Vulnerable versions: 1.4.2
Fixed in: Package removed; do not install - npm / bun Registry — js-digest
Vulnerable versions: all published
Fixed in: Package removed; do not install
Remediation for "Atomic Arch" AUR Supply-Chain Attack
Patches
- No software patch applies — remediation is removal of malicious AUR updates and malicious npm/bun packages and credential rotation
Immediate actions
- Audit any AUR packages installed or updated between 2026-06-09 and 2026-06-12 with yay/paru and rebuild from clean, vetted PKGBUILDs
- Search npm and bun caches for atomic-lockfile (v1.4.2) and js-digest and purge them (~/.npm, ~/.bun, node_modules)
- Check for the eBPF rootkit: ls /sys/fs/bpf/hidden_pids /sys/fs/bpf/hidden_names /sys/fs/bpf/hidden_inodes
- Inspect /etc/systemd/system/ and ~/.config/systemd/user/ for unexplained units referencing binaries in /var/lib/, and check /var/lib/ for the dropped ELF
- Rotate ALL credentials reachable from affected hosts: SSH keys, GitHub/npm tokens, OpenAI/cloud API keys, Vault tokens, Discord/Slack/Teams sessions, and any crypto-wallet seed phrases
Workarounds
- Block egress to the public file-sharing service temp.sh and to Tor where Tor is not required
- Manually review PKGBUILD diffs before invoking AUR helpers; disable automatic AUR updates
Longer-term hardening
- Deploy EDR with eBPF-aware/behavioral detection capable of flagging getdents64 hooking and BPF map pinning
- Treat AUR (and all user-contributed package repositories) as untrusted: review every PKGBUILD/.install/.hook before building
- Pin and lock npm/bun dependencies; enable lifecycle-script auditing and block install-time script execution (npm --ignore-scripts) where possible
- Segment developer workstations and use hardware-backed/ephemeral credentials to limit token-theft blast radius
Weaknesses (CWE) in "Atomic Arch" AUR Supply-Chain Attack
Timeline of "Atomic Arch" AUR Supply-Chain Attack
- Earliest malicious commits pushed: attackers begin adopting orphaned AUR packages and modifying PKGBUILD/.install hooks to pull atomic-lockfile.
- Compromise window opens; users building affected AUR packages with yay/paru begin installing the atomic-lockfile infostealer.
- Arch developer David Runge clarifies that maintainer 'arojas' (Antonio Rojas) was impersonated via git commit forgery, not a malicious maintainer.
- Campaign first publicly reported; ioctl.fail publishes preliminary reverse-engineering of the 'deps' ELF infostealer and eBPF rootkit.
- Arch maintainers run a large-scale deletion campaign removing malicious AUR updates and blocking attacker accounts; official Arch binary repositories confirmed unaffected.
- Community detection scripts (lenucksi/aur-malware-check) released checking for atomic-lockfile/js-digest caches, systemd persistence and /sys/fs/bpf/hidden_* eBPF maps.
- Sonatype publishes 'Atomic Arch' analysis and tracks the malicious dependency as Sonatype-2026-003775 (CVSS 8.7).
- Secondary 'bun' wave identified using package js-digest via attacker accounts custodiatovar and veramagalhaes; scope assessed at 400+ (reports up to ~588) packages.
Sources cited for "Atomic Arch" AUR Supply-Chain Attack
- 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers
- Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware
- Preliminary analysis of AUR malware (deps ELF reverse engineering)
- aur-malware-check: Detection tools for the June 2026 atomic-lockfile AUR supply-chain attack
- Attack wave on Arch Linux: hundreds of package descriptions with malware in AUR
- Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages
- AUR Packages Compromised with Infostealer and Rootkit (discussion)
- 400+ AUR Packages Compromised with Infostealer and Rootkit
Detection coverage for TL-2026-0782
As of 2026-06-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0782 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.