Arch Linux Security Alert: 400+ AUR Packages Hijacked to Deliver Lethal Rootkits
Attackers have compromised over 400 packages within the Arch User Repository (AUR), modifying build scripts to inject a Rust-based credential stealer into users' systems. This sophisticated malware is capable of deploying an eBPF rootkit on machines where build processes are executed with root privileges, allowing for deep persistence and stealthy data exfiltration. The incident highlights a significant vulnerability in community-driven software repositories, as the malicious scripts execute during the package compilation phase, potentially affecting thousands of developers and enthusiasts who rely on these community-maintained tools.