Package count is the headline. The harvested SSH keys and tokens are the real payload. Blast radius isn't 1,500 packages - it's every repo and registry those creds reach. By the time you rotate, they've pushed downstream.
Update: the Arch Linux AUR supply chain attack just got much worse.
When I posted earlier, around 400 packages were compromised.
Now it's reportedly over 1,500.
The malware isn't just stealing credentials.
It's targeting developers by harvesting:
• SSH keys
• GitHub tokens
• npm credentials
• Browser sessions
• Slack, Discord & Teams accounts
• VPN configurations
And on privileged systems, it can reportedly deploy an eBPF rootkit to hide from security tools.
This is quickly becoming one of the largest AUR compromises ever seen.
If you're an Arch user, now would be a good time to audit your recent AUR installs.