Per Bleeping Computer, the Arch Linux project has temporarily halted the adoption of new packages within its Arch User Repository (AUR) due to a significant increase in malicious takeovers of existing packages. This measure is in place while the project addresses the ongoing security concerns.The decision to disable package adoption was announced on the distribution's mailing list by contributor Robin Candau. The surge in malicious activity began around July 29, with initial reports identifying the "openconnect-sso" package as compromised. Analysis by the Independent Federated Intelligence Network (IFIN) revealed a two-stage infection process. The first stage acts as a loader, evading detection by checking for debuggers, sandboxes, and virtual machines before establishing persistence through systemd services and cron jobs. It then downloads a second-stage payload from an .onion server via a Tor client.This payload is described as Rust-based stealer malware with remote administration (RAT) and SSH worm capabilities, targeting browser credentials, cryptocurrency wallets, cloud secrets, AI service API keys, and more. The malware can also spread laterally using stolen SSH keys. This incident follows a similar campaign in June that compromised over 400 AUR packages with a rootkit and info-stealer. The current campaign is alleged to have expanded to over 200 AUR packages, including popular ones like "boringssl-git" and "icloudpd," through compromised maintainer accounts or the adoption of orphaned packages.Source: Bleeping Computer
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
