Arch Linux users are responding to a malware incident in the Arch User Repository (AUR) after multiple user-contributed packages were modified with malicious commits that attempted to fetch npm-based payloads during installation. Reports on the aur-general mailing list and a dedicated incident thread indicate the changes inserted unexpected npm commands and behavior unrelated to the original software, with the alvr package cited as a prominent example and atomic-lockfile named among the npm packages involved.
Arch maintainers and contributors have been removing the malicious changes, tracking affected packages, and banning associated accounts while the full scope remains under investigation. The incident is reported to be limited to the AUR and does not affect Arch Linux’s official package repositories; users are being urged to avoid blindly updating AUR packages and to review PKGBUILD diffs, newly added .install files, and any unexpected npm dependencies before installing updates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Arch Linux temporarily turned off new account registration for the Arch User Repository as part of its response to the malicious package campaign. The measure was taken amid cleanup of malicious package adoptions and updates affecting the community-maintained repository.
After Arch developers said the earlier AUR malware incident was under control, additional malicious packages were identified in a new wave affecting multiple categories including Node.js packages, Firefox-related packages, LibreWolf extensions, a NeoVim plug-in, and a Plasma 6 applets package. The newly found malware used obfuscated code and attempted to conceal Bun-related actions, making it harder to detect than the prior wave.
Arch Linux developers said they had deleted all malicious commits they were aware of and believed the AUR malware incident was under control. A cited list put the number of affected AUR packages at 1,579, indicating the scope had grown beyond earlier estimates of 900+ packages.
Reporting on the Atomic Arch supply-chain campaign said attackers launched a second wave that replaced the earlier npm-based payload chain with `bun install js-digest`, delivering a different malicious ELF. The update indicated the campaign expanded beyond the initial `atomic-lockfile` infostealer/rootkit delivery method.
A new report on the 'Atomic Arch' supply-chain campaign said more than 900 AUR packages were backdoored after attackers adopted orphaned packages and modified PKGBUILDs to install malicious npm packages. The report also described expanded malware capabilities, including a Rust-based credential stealer with an eBPF rootkit, systemd persistence, Tor-based communications, and possible Monero cryptomining staging.
Arch Linux said it was actively tracking malicious AUR commits and taking steps to prevent additional malicious updates from being pushed. The project warned users that AUR account creation, package updates, and package adoption or creation could be disrupted during mitigation efforts and advised users to review PKGBUILD and install script changes carefully.
Contributors opened a dedicated report thread to track affected packages, remove malicious commits, and ban related accounts. Reporting indicated the incident was limited to the AUR and did not affect Arch Linux's official package repositories.
Researchers reported that more than 400 Arch User Repository packages were compromised in a supply chain attack dubbed 'Atomic Arch,' with attackers abusing orphan-package adoption to insert malicious PKGBUILD changes. The altered scripts fetched rogue npm packages that deployed an infostealer targeting browser credentials, SSH keys, environment variables, and cryptocurrency wallet data, while Arch maintainers reverted commits and banned the attacker accounts.
A malware incident affecting Arch Linux's Arch User Repository was first reported on the aur-general mailing list, where user-contributed packages were found to contain malicious commits that attempted to download npm-based payloads during installation.
Arch Linux temporarily halted package submissions to the Arch User Repository after discovering malicious packages in the community repository. The response followed abuse of orphaned packages, with attackers modifying packages to swap npm for bun and execute malicious code via post_install scripts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
28 references tracked. Mallory keeps watching after this page renders.
phoronix.com
Open sourcephoronix.com
Open sourcescworld.com
Open sourcephoronix.com
Open sourcesonatype.com
Open sourcelists.archlinux.org
Open sourceopennet.ru
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.