More than 400 packages in the Arch User Repository (AUR) have been found to contain malware in a major supply chain attack.
According to security researchers at Sonatype, attackers took over abandoned AUR packages by posing as trusted maintainers.
They modified the packages to download a malicious npm dependency called atomic-lockfile, which contained code designed to steal information and maintain access to infected systems.
Arch Linux’s official repositories were not affected. The attack impacted only the AUR, a community-maintained collection of package build scripts.
Arch maintainers have removed the malicious packages and blocked the accounts involved. The number of affected packages grew to more than 400 before the campaign was discovered.
Sources: Sonatype researchers and Arch Linux community reports.