
AdvisoryArch User Repository (AUR) packages
Over 400 Arch Linux AUR Packages Hijacked in 'Atomic Arch' Supply-Chain Attack
Attackers adopted orphaned Arch User Repository packages and rewrote their build scripts to pull a malicious npm dependency (atomic-lockfile), delivering a Rust credential stealer with an optional root-only eBPF rootkit. Arch's official repositories were not affected.
