Threat reportSupply ChainTL-2026-0788
Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to Deliver Rust 'deps' Credential Stealer with eBPF Rootkit (Sonatype-2026-003775)
Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to (TL-2026-0788), also tracked as Atomic Arch, is a high-severity supply-chain compromise scored CVSS 8.7, first published 2026-06-14. It has no confirmed attribution, affects Arch Linux (community) Arch User Repository (AUR) packages, maps to 30 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 25 indicators of compromise.
- CVSS
- 8.7/10High
- CVEs
- 0None referenced
- Techniques
- 30MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-0788
- Threat ID
- TL-2026-0788
- Also known as
- Atomic Arch, Sonatype-2026-003775
- Severity
- HIGH
- CVSS
- 8.7 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L)
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, software development, open source, devops
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to
Malware and tooling: Custom Rust async C2 over Tor onion + temp.sh exfil
How Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to works
Threat actors hijacked 400+ orphaned Arch User Repository (AUR) packages via AUR's legitimate package-adoption workflow, modifying PKGBUILD/install hooks to pull a malicious npm package (atomic-lockfile@1.4.2) whose preinstall hook executes a bundled Rust ELF named 'deps'. The stealer harvests browser cookies, Slack/Discord/Teams/Telegram sessions, GitHub/npm/OpenAI/Vault tokens, SSH keys, Docker/Podman and VPN credentials, exfiltrates over a Tor onion C2 and temp.sh, and installs an optional eBPF rootkit (hidden_pids/hidden_names/hidden_inodes maps) when run as root.
On 11-12 June 2026 the Arch Linux community and software-supply-chain vendor Sonatype disclosed a large-scale supply-chain compromise of the Arch User Repository (AUR), tracked by Sonatype as Sonatype-2026-003775 and named the 'Atomic Arch' campaign (CVSS 8.7, no CVE assigned).
The AUR allows community members to adopt orphaned (abandoned) packages through a normal ownership-transfer workflow. The actor(s) requested ownership of established-but-unmaintained packages and, once granted maintainer rights, modified the package build scripts. Two injection patterns were observed: (1) modified PKGBUILD files / .install post-install hooks that run 'npm install atomic-lockfile' during the build, and (2) a 'preinstall' lifecycle script in the malicious npm package pointing at './src/hooks/deps'. Git commit metadata was spoofed to appear to come from established maintainer accounts, which were confirmed never to have been compromised. Sonatype's first write-up counted ~20 hijacked packages; within a day community trackers grepping the AUR git mirror cataloged ~408, and a second wave (using 'bun install js-digest' from separate accounts) reportedly pushed the total well past 1,500 packages. Named affected packages include alvr, premake-git and monero-wallet-gui.
The payload is a 3,040,376-byte stripped Linux ELF64 (x86-64, PIE) named 'deps' (SHA-256 6144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98b), written in Rust using async state machines. On execution it redirects stdin/stdout/stderr to /dev/null, ignores SIGPIPE, and uses flock() to enforce a single instance. It establishes a local SOCKS-style proxy on 127.0.0.1 and tunnels a POST /api/agent request to a hardcoded Tor onion C2 (olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion) whose address is XOR-obfuscated in the binary (32-byte repeating key). It downloads a Tor expert bundle and can fetch a second-stage binary from the onion '/bin/linux' path (verified via '/bin/sha256/linux').
The stealer enumerates ~27 Chromium-family browser variants (Chrome, Edge, Brave, Vivaldi, Opera, Yandex, Epic, Iridium, Thorium, etc., including Flatpak/Snap paths) for Local Storage leveldb, Network/Cookies and encrypted cookie values; 15+ Electron collaboration clients (Slack, Microsoft Teams, Discord/PTB/Canary, plus Vesktop, Legcord, WebCord, ArmCord, Vencord and others); and developer/local secrets: ~/.ssh keys and known_hosts, shell histories (bash/zsh/fish), HashiCorp Vault tokens (/.vault-token), PuTTY keys, .ovpn VPN profiles, and Docker/Podman registry credentials. It validates and enriches stolen sessions live against api.github.com, registry.npmjs.org, api.openai.com, Slack, Teams and Discord APIs through the local SOCKS layer, then exfiltrates multi-part archives to temp.sh via POST /upload.
When geteuid()==0 and /proc/self/status shows CAP_BPF and/or CAP_SYS_ADMIN in CapEff, 'deps' loads an eBPF rootkit using pinned maps /sys/fs/bpf/hidden_pids, /sys/fs/bpf/hidden_names and /sys/fs/bpf/hidden_inodes to hide PIDs from /proc, hide process names in directory listings, hide socket inodes from /proc/net/tcp and netlink diagnostics, and block ptrace attachment against hidden processes. The eBPF component cannot escalate privileges on its own. Persistence is via systemd: a generated .service unit under /etc/systemd/system/ (root) or ~/.config/systemd/user/ (non-root) with Restart=always, RestartSec=30, and the executable copied below /var/lib/. Because of the rootkit's persistence and hiding capability, responders are advised to rotate all exposed credentials and rebuild affected hosts from trusted media rather than attempt in-place cleanup.
MITRE ATT&CK techniques used in TL-2026-0788
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Defense Evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1480 Execution Guardrails; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
stealth
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery
Initial Access
initial-access
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Persistence
T1543 Create or Modify System Process
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1608 Stage Capabilities
defense-impairment
Affected products and versions in Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to
- Arch Linux (community) — Arch User Repository (AUR) packages
Vulnerable versions: 400+ orphaned packages adopted/modified June 2026 (e.g. alvr, premake-git, monero-wallet-gui)
Fixed in: malicious packages flagged/removed by AUR moderators - npm (registry) — atomic-lockfile
Vulnerable versions: 1.4.2
Fixed in: removed from npm registry - npm (registry) — js-digest (second wave)
Vulnerable versions: second-wave variant
Fixed in: removed from npm registry - Arch-derived distributions — EndeavourOS / Manjaro / WSL2 Arch (AUR users)
Vulnerable versions: systems building affected AUR packages
Remediation for Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to
Patches
- No vendor patch / CVE — AUR is community-maintained; affected packages were flagged and removed by AUR moderators and the malicious npm packages (atomic-lockfile, js-digest) were taken down
Immediate actions
- Audit AUR install/build history since early June 2026 for 'npm install atomic-lockfile' or 'bun install js-digest' in PKGBUILD, .install hooks, makepkg logs and package caches
- Check for unknown systemd services under /etc/systemd/system/ and ~/.config/systemd/user/ with Restart=always/RestartSec=30
- Inspect /sys/fs/bpf/ for pinned maps named hidden_pids, hidden_names, hidden_inodes
- Look for unexpected ELF executables under /var/lib/ and any 'src/hooks/deps' artifact in npm package directories
- Block outbound Tor and connections to the onion C2; alert on POST /upload to temp.sh from build/dev hosts
Workarounds
- Avoid installing/updating recently-adopted AUR packages until the package's PKGBUILD is manually reviewed
- Manually inspect PKGBUILD and .install files before makepkg for any npm/bun install of unfamiliar packages
Longer-term hardening
- Rotate ALL credentials that touched affected hosts: SSH keys, GitHub/npm/OpenAI/Vault tokens, Slack/Discord/Teams sessions, Docker/Podman registry creds, VPN profiles, SSO
- Treat compromised hosts as fully owned: rebuild from trusted media due to eBPF rootkit persistence
- Run AUR builds in isolated/ephemeral sandboxes without network egress to package-install hooks
- Deploy eBPF/behavioral EDR capable of detecting unauthorized BPF program/map loads
Weaknesses (CWE) in Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to
Timeline of Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to
- Atomic Arch campaign goes active: orphaned AUR packages adopted via ownership transfer and PKGBUILD/install hooks modified to pull malicious atomic-lockfile npm package.
- The Hacker News and BleepingComputer publish coverage; IOC SHA-256 6144d433...3c98b and onion C2 disclosed.
- Community defenders publish checker scripts (e.g. the Kidev AUR malware-checker gist) so Arch users can scan locally installed AUR packages for the malicious atomic-lockfile/js-digest PKGBUILD install hooks and the 'deps' ELF.
- AUR moderators flag/remove malicious packages; atomic-lockfile and js-digest removed from npm registry; community checker scripts published.
- Second wave observed using 'bun install js-digest' from separate accounts; trackers report totals climbing past 1,500 packages.
- Arch community aur-general thread and git-mirror grep catalog ~408 compromised packages; Whanos/ioctl.fail publishes preliminary malware analysis of the 'deps' ELF.
- Sonatype publishes first write-up (~20 hijacked packages) tracking the campaign as Sonatype-2026-003775 (CVSS 8.7), naming it 'Atomic Arch'.
- Vendor write-ups (StepSecurity, Latest Hacking News) report no confirmed actor attribution but link the campaign to the broader 'Atomic' npm infostealer ecosystem reusing the same Tor/temp.sh exfiltration pattern; defenders urged to treat eBPF-rootkit hosts as fully compromised and rebuild from trusted media.
- StepSecurity and other vendors publish defender guidance: rotate credentials, rebuild affected hosts from trusted media due to eBPF rootkit persistence.
Sources cited for Atomic Arch: 400+ Arch Linux AUR Packages Hijacked to
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
- Over 400 Arch Linux packages compromised to push rootkit, infostealer
- Preliminary analysis of the AUR malware ('deps')
- 400+ AUR Packages Hijacked: What the Atomic Arch Campaign Means for Supply-Chain Security
- Atomic Arch: 400+ AUR Packages Backdoored with eBPF Rootkit and Credential Stealer
- Sonatype: atomic-arch npm campaign adds malicious dependency (Sonatype-2026-003775)
- IFIN discourse: 400 AUR packages compromised with infostealer and rootkit
- Kidev AUR malware checker script
Detection coverage for TL-2026-0788
As of 2026-06-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0788 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.