Back to Intel

Intel Node

400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer

lowmalware2026-06-12T19:24:50+00:00source excerpt
malwarelinux

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself.

Read Original Source