# "Atomic Arch" AUR Supply-Chain Attack: 400+ Orphaned Arch User Repository Packages Backdoored via Malicious npm Dependencies (atomic-lockfile / js-digest) Deploying a Linux Infostealer with eBPF Rootkit

> Threat actors hijacked 400+ orphaned Arch User Repository (AUR) packages — partly by forging git commits to impersonate KDE maintainer 'arojas' — and modified their PKGBUILD/.install hooks to silently pull malicious npm/bun packages (atomic-lockfile, js-digest). The packages dropped a multi-stage Linux ELF infostealer ('deps') that exfiltrates browser credentials, SSH keys, cloud/dev tokens and crypto-wallet data to a Tor onion C2, with optional root-only eBPF rootkit process/file/socket hiding. Official Arch binary repositories were unaffected.

- **Published:** 2026-06-12T00:00:00Z
- **Last reviewed:** 2026-06-12T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0782
- **ID:** TL-2026-0782
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Between June 9 and June 12, 2026 a coordinated supply-chain campaign — dubbed "Atomic Arch" by Sonatype — abused the open ownership-claim and contribution model of the Arch User Repository (AUR). The AUR is a community-driven repository of user-submitted PKGBUILD build recipes that AUR helpers such as `yay` and `paru` execute on the end-user's machine; it is explicitly outside Arch Linux's signed binary repositories. Attackers targeted orphaned-but-trusted packages with existing install bases to maximize reach while minimizing scrutiny.

For a portion of the campaign the attackers forged git commit authorship to impersonate legitimate KDE/Arch maintainer 'arojas' (Antonio Rojas), who Arch developer David Runge clarified was NOT a malicious maintainer but an impersonation victim. Additional attacker-controlled AUR accounts (custodiatovar, veramagalhaes) pushed a secondary wave using the bun package manager and the js-digest package. The malicious npm/bun packages were published under accounts including 'herbsobering' and 'krisztinavarga'.

The poisoned PKGBUILDs added a post-install/.install/.hook step running `npm install atomic-lockfile minimist chalk` (and a parallel `bun install js-digest` wave). atomic-lockfile v1.4.2 carried a `"preinstall": "./src/hooks/deps"` lifecycle hook pointing at a bundled 3,040,376-byte x86-64 PIE ELF (SHA256 6144D433F8A0316869877B5F834C801251BBB936E5F1577C5680878C7443C98B). On execution the stealer harvests Chromium-family browser cookies/credentials (Chrome, Edge, Brave, Vivaldi, Opera), Firefox profiles, SSH private keys, shell histories (.bash_history/.zsh_history/fish_history), GitHub/npm/Slack/Discord/Microsoft Teams/Telegram tokens, HashiCorp Vault tokens, Docker/Podman credentials, VPN (.ovpn) profiles, /etc/machine-id, and cryptocurrency wallet data (including Monero monero-wallet-gui artifacts) and seed phrases. It validates harvested tokens against api.openai.com, api.github.com, registry.npmjs.org, discord.com and teams.microsoft.com.

A decoded 62-byte ciphertext at offset 0x2DA96, deobfuscated with a 32-byte repeating XOR key at 0x1AA60, yields the primary C2 onion host olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion. The stealer beacons via `POST /api/agent HTTP/1.0` over TCP/80 and TCP/8080 using a SOCKS-style local transport on 127.0.0.1, stages a secondary Linux binary from <onion>/bin/linux (verified against <onion>/bin/sha256/linux, reference hash 47893d9badc38c54b71321263ce8178c1abb10396e0aadf9793e61ec8829e204), and exfiltrates collected archives to the public temp.sh service via `POST /upload HTTP/1.1`. Persistence is via systemd: root installs copy the binary to /var/lib/ with a unit under /etc/systemd/system/, while non-root installs use ~/.config/systemd/user/, both with Restart=always / RestartSec=30, using /proc/self/exe and flock() for single-instance control. When running as root (geteuid()==0 with CAP_BPF / CAP_SYS_ADMIN) the malware loads an eBPF program (scales.bpf.c) that hooks getdents64() and pins maps at /sys/fs/bpf/hidden_pids, /sys/fs/bpf/hidden_names and /sys/fs/bpf/hidden_inodes to hide its PIDs, process names and socket inodes from /proc, ps and htop, and kills attempted ptrace attachments. Sonatype tracks the malicious dependency as Sonatype-2026-003775 (vendor CVSS 8.7). No CVE was assigned (an abuse-of-trust supply-chain compromise rather than a software vulnerability). Arch maintainers ran a large-scale deletion campaign removing malicious updates and blocking attacker accounts; official Arch repositories were never affected.

## MITRE ATT&CK

- T1584 Compromise Infrastructure
- T1587 Develop Capabilities
- T1585 Establish Accounts
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1543 Create or Modify System Process
- T1548 Abuse Elevation Control Mechanism
- T1014 Rootkit
- T1027 Obfuscated Files or Information
- T1564 Hide Artifacts
- T1622 Debugger Evasion
- T1036 Masquerading
- T1552 Unsecured Credentials
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1082 System Information Discovery
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1573 Encrypted Channel
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel

## Sources

- [400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers](https://cybersecuritynews.com/arch-linux-aur-packages-compromised/)
- [Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware](https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency)
- [Preliminary analysis of AUR malware (deps ELF reverse engineering)](https://ioctl.fail/preliminary-analysis-of-aur-malware/)
- [aur-malware-check: Detection tools for the June 2026 atomic-lockfile AUR supply-chain attack](https://github.com/lenucksi/aur-malware-check)
- [Attack wave on Arch Linux: hundreds of package descriptions with malware in AUR](https://www.heise.de/en/news/Attack-wave-on-Arch-Linux-hundreds-of-package-descriptions-with-malware-in-AUR-11330290.html)
- [Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages](https://linuxiac.com/arch-linux-aur-malware-campaign-hits-multiple-user-contributed-packages/)
- [AUR Packages Compromised with Infostealer and Rootkit (discussion)](https://news.ycombinator.com/item?id=48500447)
- [400+ AUR Packages Compromised with Infostealer and Rootkit](https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0782
