Friday, 12 June 2026

400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer

iT4iNT SERVER Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them.

The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself. The AUR is Arch Linux's community package collection, and it is separate VDS VPS Cloud


http://dlvr.it/TT1GkG

No comments:

Post a Comment

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

iT4iNT SERVER A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email cre...