Third wave of attacks on the AUR

Arch Linux disables package adoption in the AUR due to new malware wave

Backdoor, Linux, Linux security, Linux backdoor, Velvet Ant, linux login hack, hackers manipulate Linux login systems with backdoors, decade-long Linux cyber espionage campaign exposed, Linux Login, Hacker
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Stanislaw Mikulski / Shutterstock.com

The Arch Linux project has temporarily disabled the adoption of orphaned packages in the Arch User Repository, or AUR for short.

The decision was announced by contributor Robin Candau on the project’s mailing list. Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, the adoption feature is temporarily disabled while the team handles the situation, Candau explained. Users were also asked to report suspicious adoptions or commits and to stay vigilant.

Ad

Back in June, a first, significantly larger wave of attacks had already hit the AUR, originally involving more than 400 compromised packages, with the actual number later estimated at around 1,500 following further investigation. Arch developers cleaned up the repository at the time, removing more than 1,900 compromised packages, and temporarily suspended new account registrations before declaring the repository cleaned up in mid-June and reopening registration on July 13. According to security researchers from the Independent Federated Intelligence Network, or IFIN for short, the campaign continued in a second and now third wave despite this cleanup, with the current wave beginning on July 29 with the package openconnect-sso and using a technical architecture that differs from the June campaign.

Two-stage infection with Tor connectivity on Linux

According to IFIN’s technical analysis, this is a two-stage infection chain. The first stage acts as a loader that first checks whether it is running in a debugging environment, a sandbox, a virtual machine, or a CI/CD environment in order to evade detection. If this is not the case, the loader establishes persistent access via systemd services and cron jobs and then downloads a Tor client disguised as dbus-daemon, through which the second stage is fetched from an .onion server.

This second stage is malware written in the Rust programming language with infostealer, remote access, and SSH worm capabilities. Among other things, it targets credentials stored in browsers, cryptocurrency wallets, data from password managers, cloud and developer secrets, API keys for AI services, SSH keys, and access tokens for messaging platforms. It also allows attackers to execute commands over an encrypted Tor channel and can use stolen SSH keys to copy and execute itself independently on further systems.

Ad

More than 200 affected packages reported so far

According to a Reddit user tracking the campaign, it has since expanded to more than 200 AUR packages, either through compromised maintainer accounts or through the adoption of orphaned packages. Among those named are the comparatively popular packages boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server. Independent confirmation of the compromised status of these packages is not yet available, and a complete list of all roughly 200 suspected affected packages had not been provided as of publication.

(red)

Ad

Weitere Artikel