Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 2 sources · 9 days · First seen · Last updated
Arch Linux AUR supply-chain attacks
Overview
The Arch Linux DevOps team temporarily suspended the package-adoption feature of the Arch User Repository (AUR) following a wave of malicious supply-chain attacks. Attackers exploited policies allowing community members to adopt orphaned packages, injecting harmful build scripts into over 400 community-maintained packages to facilitate credential theft, remote code execution, or backdoor installations.
Following the investigation into these coordinated attacks, which have been referred to as ‘Atomic Arch’, the AUR governance model was modified. The campaign targeted orphaned packages using compiled ELF binaries and obfuscated shell downloaders to bypass security filters. In response, Arch Linux transitioned from an automatic transfer system to a manual review process. Package adoption now requires approval from a Package Maintainer, and only one adoption request can be pending per package base at any given time. Additionally, new account creations remain blocked.
Entities
Timeline
-
2 days ago
[TECHNOLOGY] 2 sourcesArch Linux implements manual AUR package adoption to combat malwareArch Linux has introduced manual review requirements for AUR package adoption following the ‘Atomic Arch’ malware campaign, which targeted over 200 orphaned packages with malicious code.
-
11 days ago
[TECHNOLOGY] 3 sourcesArch Linux Suspends AUR Package Adoption After Malicious Supply‑Chain AttacksArch Linux has halted AUR package adoption after attackers compromised over 400 community packages, injecting malicious code. The move, announced by Robin Candau, aims to stop further spread while the issue is
Sources
blog.fredericbezies-ep.fr · it-boltwise.de