DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // ATOMIC-ARCH-CAMPAIGNFIRST SEEN: JUN 2026

ATOMIC ARCH (UNK Threat Actor)

ALSO KNOWN AS: arojas (AUR username used in attack), Sonatype-2026-003775
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (unattributed as of June 13, 2026)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:JUN 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL65/100
RESOURCES65/100
PERSISTENCE68/100
STEALTH60/100
IMPACT74/100

Atomic Arch is a large-scale, actively expanding supply chain campaign first detected by Sonatype on June 11, 2026, in which an unidentified threat actor systematically adopted orphaned Arch Linux AUR packages and injected malicious PKGBUILD scripts to deploy a Rust-based credential stealer ('deps') and optional eBPF rootkit. By June 12 a second wave emerged using Bun-based delivery, and the total affected package count grew to approximately 1,500 — one of the largest documented AUR compromises on record. The attack targets developer workstations specifically, aiming to harvest credentials that enable lateral movement into enterprise environments without direct exploitation.

Developer credential harvesting (SSH keys, GitHub tokens, cloud API keys, browser sessions, cryptocurrency wallets) for downstream infrastructure access and potential cryptomining

AUR orphaned-package adoption (trust-inheritance, not typosquatting), PKGBUILD/post-install script injection, malicious npm dependency (atomic-lockfile, js-digest, lockfile-js) delivery, Rust ELF credential stealer ('deps') with SSH/GitHub/Docker/Vault/browser/Slack/Discord/Teams harvest, eBPF rootkit for process/file/socket hiding (CAP_BPF required), anti-debugging, git commit metadata spoofing to impersonate trusted maintainers, staged cryptominer payload (Monero)

SOFTWARE DEVELOPERS
DEVOPS/CI-CD ENVIRONMENTS
OPEN-SOURCE ECOSYSTEM
LINUX USERS
CRYPTOCURRENCY HOLDERS

npm registry (malicious packages: atomic-lockfile@1.4.2, js-digest, lockfile-js), AUR (compromised under username 'arojas'), Bun package runtime (second wave), eBPF pinned BPF maps (hidden_pids, hidden_names, hidden_inodes); Arch Linux has deleted known malicious commits and is actively mitigating

FILE DATE: JUN 2026
Atomic Arch — Wave 1 (npm/atomic-lockfile)
On June 11, 2026, attacker operating as 'arojas' adopted 408 orphaned AUR packages and injected atomic-lockfile npm payload; Sonatype assigned CVSS 8.7 (Sonatype-2026-003775) and published same-day disclosure.
FILE DATE: JUN 2026
Atomic Arch — Wave 2 (Bun/js-digest expansion)
On June 12, 2026, a second wave replaced npm delivery with ██████████████████████ total affected packages grew to ~1,500 with analysis still ongoing as of June 13, 2026.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn