Story perspectives
400+ AUR Packages Hijacked, Arch Urges Credential Rotation
6/13/2026
1 of 1
Story summary
- Attackers hijacked over 400 Arch Linux User Repository (AUR) packages this week, adding a Rust credential-stealer.
- The compromised PKGBUILD scripts run “npm install atomic-lockfile” or “bun install js-digest” and exfiltrate cookies, tokens and SSH keys to temp.sh and a Tor onion server.
- Arch Linux maintainers are resetting the commits, banning the uploaders, and urging users who updated AUR packages after June 11 to verify against the community list and rotate credentials.
