400 AUR packages backdoored. Campaign's being called "Atomic Arch," started June 11.
Attacker claimed orphaned packages through AUR's own adoption process, then slipped a Rust infostealer and eBPF rootkit into PKGBUILDs via npm post-install hooks.
The eBPF rootkit hides PIDs and sockets from ps, ss, and /proc. Standard live response is blind on a rooted host. Don't try to clean from inside the same OS.
Run pacman -Qm and cross-ref the compromised package list. Anything installed after June 11, rotate everything. SSH keys, API tokens, browser creds, all of it.
Detection script at
github.com/lenucksi/aur-malw…
Manjaro, EndeavourOS, Garuda users you're in scope too.