Over 400 Arch Linux packages compromised to push rootkit, infostealer
What happened
Researchers reported that over 400 Arch Linux AUR packages were modified to distribute a rootkit and credential‑stealing malware via malicious preinstall scripts. The compromise used takeover of orphaned packages and PKGBUILD modifications to push a trojanized npm dependency, making developer installs and CI builds operationally risky. Procurement should watch suppliers and teams that rely on unvetted community packages and require provenance controls or blocklists
Why the category manager should care
Assume community package sources are untrusted until proven otherwise; require SBOMs or provenance for vendor‑supplied build artifacts
Key facts
- Over 400 AUR packages reported distributing malicious payloads
- Attack vector: PKGBUILD modifications and malicious preinstall scripts
- Malware includes credential stealer and optional rootkit components