Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The Arch User Repository (AUR) suspended new registrations Monday due to an ongoing supply chain attack flooding the repository with more than 1,500 malicious packages.
In an initial wave affecting about 400 packages, this script executed an npm install command for a package called atomic-lockfile. Shortly afterward, the attackers switched tactics, instead using the Bun runtime to install packages called js-digest and lockfile-js
atomic-lockfile ‘s package.json contains a preinstall lifecycle hook: "preinstall": "./src/hooks/deps"
A user runs their AUR helper ( yay , paru , or raw makepkg ) to install or update a package.
Beyond data theft, the malware employed rootkit-style persistence techniques, disguising its active processes as legitimate kernel threads to evade detection by standard process monitors like ps and htop.
The outer package is a largely functional TypeScript npm package (legitimate atomic-lockfile project) with the ELF binary inserted into its source tree.
Beyond data theft, the malware employed rootkit-style persistence techniques, disguising its active processes as legitimate kernel threads to evade detection by standard process monitors like ps and htop.
A user runs their AUR helper ( yay , paru , or raw makepkg ) to install or update a package.
This means a developer workstation, maintainer machine, or CI/build host could execute the malware as a side effect of building or installing the compromised AUR package.
Once installed, the malicious npm packages deployed a multi-stage infostealer payload engineered to exfiltrate a broad range of sensitive data, including: Browser credentials — saved passwords, session cookies, and autofill data from Chromium and Firefox-based browsers.
SSH private keys — enabling attackers to pivot to remote servers and infrastructure System environment variables — potentially exposing API tokens, cloud credentials, and application secrets Cryptocurrency wallet data — targeting local wallet files and seed phrases.
Once installed, the malicious npm packages deployed a multi-stage infostealer payload engineered to exfiltrate a broad range of sensitive data, including: Browser credentials — saved passwords, session cookies, and autofill data from Chromium and Firefox-based browsers.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious package used in a second wave of the AUR supply-chain attack; installed via bun install and used to fetch and execute a different malicious payload.
A malicious package used in the second wave of the campaign via bun install. It delivered a malicious ELF payload and served as an alternate delivery mechanism to the earlier atomic-lockfile stage.
A second malicious npm package used in a follow-on wave of the Atomic Arch campaign. It delivered the same deps ELF payload through a different installation toolchain to evade detections focused on atomic-lockfile.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.