
Arch AUR Supply-Chain Breach Hits 400+ Packages with Credential Stealer and eBPF Rootkit
A supply-chain attack hijacked more than 400 Arch Linux AUR packages by modifying their build scripts to install a Rust-based credential stealer that can also load an eBPF rootkit when run with root; the attackers targeted abandoned packages to exploit trust, persisted via systemd, and used Tor for C2, prompting users to audit builds, rotate credentials, and thoroughly clean systems rather than assuming safety from package managers.