Threat reportSupply ChainTL-2026-0788

Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to Deliver Rust 'deps' Credential Stealer with eBPF Rootkit (Sonatype-2026-003775)

highACTIVE

Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to (TL-2026-0788), also tracked as Atomic Arch, is a high-severity supply-chain compromise scored CVSS 8.7, first published 2026-06-14. It has no confirmed attribution, affects Arch Linux (community) Arch User Repository (AUR) packages, maps to 30 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 25 indicators of compromise.

CVSS
8.7/10High
CVEs
0None referenced
Techniques
30MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0788

Threat ID
TL-2026-0788
Also known as
Atomic Arch, Sonatype-2026-003775
Severity
HIGH
CVSS
8.7 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L)
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software development, open source, devops
Target regions
Global
Detection rules
9
Indicators of compromise
25

Malware and tooling in Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to

Malware and tooling: Custom Rust async C2 over Tor onion + temp.sh exfil

How Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to works

Threat actors hijacked 400+ orphaned Arch User Repository (AUR) packages via AUR's legitimate package-adoption workflow, modifying PKGBUILD/install hooks to pull a malicious npm package (atomic-lockfile@1.4.2) whose preinstall hook executes a bundled Rust ELF named 'deps'. The stealer harvests browser cookies, Slack/Discord/Teams/Telegram sessions, GitHub/npm/OpenAI/Vault tokens, SSH keys, Docker/Podman and VPN credentials, exfiltrates over a Tor onion C2 and temp.sh, and installs an optional eBPF rootkit (hidden_pids/hidden_names/hidden_inodes maps) when run as root.

On 11-12 June 2026 the Arch Linux community and software-supply-chain vendor Sonatype disclosed a large-scale supply-chain compromise of the Arch User Repository (AUR), tracked by Sonatype as Sonatype-2026-003775 and named the 'Atomic Arch' campaign (CVSS 8.7, no CVE assigned).

The AUR allows community members to adopt orphaned (abandoned) packages through a normal ownership-transfer workflow. The actor(s) requested ownership of established-but-unmaintained packages and, once granted maintainer rights, modified the package build scripts. Two injection patterns were observed: (1) modified PKGBUILD files / .install post-install hooks that run 'npm install atomic-lockfile' during the build, and (2) a 'preinstall' lifecycle script in the malicious npm package pointing at './src/hooks/deps'. Git commit metadata was spoofed to appear to come from established maintainer accounts, which were confirmed never to have been compromised. Sonatype's first write-up counted ~20 hijacked packages; within a day community trackers grepping the AUR git mirror cataloged ~408, and a second wave (using 'bun install js-digest' from separate accounts) reportedly pushed the total well past 1,500 packages. Named affected packages include alvr, premake-git and monero-wallet-gui.

The payload is a 3,040,376-byte stripped Linux ELF64 (x86-64, PIE) named 'deps' (SHA-256 6144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98b), written in Rust using async state machines. On execution it redirects stdin/stdout/stderr to /dev/null, ignores SIGPIPE, and uses flock() to enforce a single instance. It establishes a local SOCKS-style proxy on 127.0.0.1 and tunnels a POST /api/agent request to a hardcoded Tor onion C2 (olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion) whose address is XOR-obfuscated in the binary (32-byte repeating key). It downloads a Tor expert bundle and can fetch a second-stage binary from the onion '/bin/linux' path (verified via '/bin/sha256/linux').

The stealer enumerates ~27 Chromium-family browser variants (Chrome, Edge, Brave, Vivaldi, Opera, Yandex, Epic, Iridium, Thorium, etc., including Flatpak/Snap paths) for Local Storage leveldb, Network/Cookies and encrypted cookie values; 15+ Electron collaboration clients (Slack, Microsoft Teams, Discord/PTB/Canary, plus Vesktop, Legcord, WebCord, ArmCord, Vencord and others); and developer/local secrets: ~/.ssh keys and known_hosts, shell histories (bash/zsh/fish), HashiCorp Vault tokens (/.vault-token), PuTTY keys, .ovpn VPN profiles, and Docker/Podman registry credentials. It validates and enriches stolen sessions live against api.github.com, registry.npmjs.org, api.openai.com, Slack, Teams and Discord APIs through the local SOCKS layer, then exfiltrates multi-part archives to temp.sh via POST /upload.

When geteuid()==0 and /proc/self/status shows CAP_BPF and/or CAP_SYS_ADMIN in CapEff, 'deps' loads an eBPF rootkit using pinned maps /sys/fs/bpf/hidden_pids, /sys/fs/bpf/hidden_names and /sys/fs/bpf/hidden_inodes to hide PIDs from /proc, hide process names in directory listings, hide socket inodes from /proc/net/tcp and netlink diagnostics, and block ptrace attachment against hidden processes. The eBPF component cannot escalate privileges on its own. Persistence is via systemd: a generated .service unit under /etc/systemd/system/ (root) or ~/.config/systemd/user/ (non-root) with Restart=always, RestartSec=30, and the executable copied below /var/lib/. Because of the rootkit's persistence and hiding capability, responders are advised to rotate all exposed credentials and rebuild affected hosts from trusted media rather than attempt in-place cleanup.

MITRE ATT&CK techniques used in TL-2026-0788

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1480 Execution Guardrails; T1564 Hide Artifacts

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

stealth

T1078 Valid Accounts

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

Initial Access

T1195 Supply Chain Compromise

initial-access

T1195 Supply Chain Compromise

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Persistence

T1543 Create or Modify System Process

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Resource Development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1608 Stage Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to

  • Arch Linux (community) — Arch User Repository (AUR) packages
    Vulnerable versions: 400+ orphaned packages adopted/modified June 2026 (e.g. alvr, premake-git, monero-wallet-gui)
    Fixed in: malicious packages flagged/removed by AUR moderators
  • npm (registry) — atomic-lockfile
    Vulnerable versions: 1.4.2
    Fixed in: removed from npm registry
  • npm (registry) — js-digest (second wave)
    Vulnerable versions: second-wave variant
    Fixed in: removed from npm registry
  • Arch-derived distributions — EndeavourOS / Manjaro / WSL2 Arch (AUR users)
    Vulnerable versions: systems building affected AUR packages

Remediation for Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to

Patches

  • No vendor patch / CVE — AUR is community-maintained; affected packages were flagged and removed by AUR moderators and the malicious npm packages (atomic-lockfile, js-digest) were taken down

Immediate actions

  • Audit AUR install/build history since early June 2026 for 'npm install atomic-lockfile' or 'bun install js-digest' in PKGBUILD, .install hooks, makepkg logs and package caches
  • Check for unknown systemd services under /etc/systemd/system/ and ~/.config/systemd/user/ with Restart=always/RestartSec=30
  • Inspect /sys/fs/bpf/ for pinned maps named hidden_pids, hidden_names, hidden_inodes
  • Look for unexpected ELF executables under /var/lib/ and any 'src/hooks/deps' artifact in npm package directories
  • Block outbound Tor and connections to the onion C2; alert on POST /upload to temp.sh from build/dev hosts

Workarounds

  • Avoid installing/updating recently-adopted AUR packages until the package's PKGBUILD is manually reviewed
  • Manually inspect PKGBUILD and .install files before makepkg for any npm/bun install of unfamiliar packages

Longer-term hardening

  • Rotate ALL credentials that touched affected hosts: SSH keys, GitHub/npm/OpenAI/Vault tokens, Slack/Discord/Teams sessions, Docker/Podman registry creds, VPN profiles, SSO
  • Treat compromised hosts as fully owned: rebuild from trusted media due to eBPF rootkit persistence
  • Run AUR builds in isolated/ephemeral sandboxes without network egress to package-install hooks
  • Deploy eBPF/behavioral EDR capable of detecting unauthorized BPF program/map loads

Weaknesses (CWE) in Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to

CWE-506, CWE-829, CWE-494, CWE-1357

Timeline of Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to

  • Atomic Arch campaign goes active: orphaned AUR packages adopted via ownership transfer and PKGBUILD/install hooks modified to pull malicious atomic-lockfile npm package.
  • The Hacker News and BleepingComputer publish coverage; IOC SHA-256 6144d433...3c98b and onion C2 disclosed.
  • Community defenders publish checker scripts (e.g. the Kidev AUR malware-checker gist) so Arch users can scan locally installed AUR packages for the malicious atomic-lockfile/js-digest PKGBUILD install hooks and the 'deps' ELF.
  • AUR moderators flag/remove malicious packages; atomic-lockfile and js-digest removed from npm registry; community checker scripts published.
  • Second wave observed using 'bun install js-digest' from separate accounts; trackers report totals climbing past 1,500 packages.
  • Arch community aur-general thread and git-mirror grep catalog ~408 compromised packages; Whanos/ioctl.fail publishes preliminary malware analysis of the 'deps' ELF.
  • Sonatype publishes first write-up (~20 hijacked packages) tracking the campaign as Sonatype-2026-003775 (CVSS 8.7), naming it 'Atomic Arch'.
  • Vendor write-ups (StepSecurity, Latest Hacking News) report no confirmed actor attribution but link the campaign to the broader 'Atomic' npm infostealer ecosystem reusing the same Tor/temp.sh exfiltration pattern; defenders urged to treat eBPF-rootkit hosts as fully compromised and rebuild from trusted media.
  • StepSecurity and other vendors publish defender guidance: rotate credentials, rebuild affected hosts from trusted media due to eBPF rootkit persistence.

Sources cited for Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to

Detection coverage for TL-2026-0788

As of 2026-06-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0788 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats