bleeping-computer · Crawled Jul 31, 2026

Arch Linux disables AUR package adoption to stop malware flood

8 IoCs
Read original article ↗

AI Summary

Arch Linux has temporarily disabled package adoption in its Arch User Repository (AUR) due to a surge in malicious package takeovers. A recent campaign began on July 29, 2026, with the compromise of the 'openconnect-sso' package, deploying a two-stage malware loader that evades analysis environments and uses Tor for C2. The second-stage payload is a Rust-based infostealer with remote access and lateral movement capabilities via SSH, targeting credentials, crypto wallets, API keys, and SSH keys.

AI-extracted · verify before operational use

Indicators of Compromise 8 extracted

Type Value Detail
Package openconnect-sso Details →
Package boringssl-git Details →
Package icloudpd Details →
Package windscribe-cli-v2-bin Details →
Package stirling-pdf-desktop-bin Details →
Package arduino-language-server-noclang-bin Details →
Package pgadmin4-server Details →
Filename dbus-daemon Details →