Arch Linux contributor Robin Candau announced that package adoption has been disabled while the project investigates the situation.

The restriction affects orphaned AUR packages, which are normally available for other maintainers to adopt. Attackers can exploit this process by taking over abandoned packages and adding malicious code to later releases.

Users have been urged to report suspicious adoption events or commits and remain cautious when installing AUR software.

Campaign reportedly began with openconnect-sso

Researchers at the Independent Federated Intelligence Network said the latest AUR package malware campaign began on 29 July with the openconnect-sso package.

The activity reportedly shares similarities with an earlier campaign, including the use of the Tor network to host or retrieve malicious payloads.

In June, a separate attack used more than 400 AUR packages to distribute Linux rootkits and information-stealing malware. The latest campaign appears to use a two-stage infection chain.

Malware targets passwords, wallets and developer secrets

The first stage acts as a loader. It checks for debuggers, virtual machines, sandboxes and CI/CD environments before creating systemd services and cron jobs for persistence.

It then downloads a Tor client disguised as dbus-daemon and uses it to retrieve a second-stage payload from a .onion service.

Researchers describe the second stage as a Rust-based infostealer for Linux x86_64 systems. It can target browser credentials, cryptocurrency wallets, password-manager data, cloud credentials, developer secrets, AI service API keys, SSH keys and messaging tokens.

The payload can also receive remote commands through an encrypted Tor channel. In addition, it may use stolen SSH keys to copy itself to other systems.

More than 200 packages may be involved

One researcher tracking the campaign claimed it may have spread to more than 200 AUR packages through compromised maintainer accounts or abandoned package adoptions.

Reportedly affected packages include boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin and pgadmin4-server.

However, the reported status of these packages has not been independently confirmed. A complete list of the suspected malicious packages was also not available at publication.


0 responses to “Arch Linux Disables AUR Package Adoption After Malware Surge”