Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Vira Manti

Published Jun 13, 2026, 1:11 AM UTC

Source: SecuritySource
- Over 400 Arch AUR packages hijacked. Attackers swapped build scripts for Rust infostealers and eBPF rootkits. Your dev secrets? Gone. Your system? Compromised. We're threadbare when community repos lack verification. Stop kidding yourself that "it won't happen to me." Check the seals on every package before you compile. If the hash manifest doesn't match, don't relay it. This isn't hype; it's a breach of trust in digital infrastructure. Secure your stack-eye, audit your builds, and assume every unverified binary is a trap. Delivery signature applied: stay paranoid.