AUR Package Adoption Suspended After Coordinated Malicious Takeover Campaign Injects Tor-Based Credential-Stealing Payload Across 200+ Packages, Including openconnect-sso
Arch Linux suspended AUR package adoption on July 30 after investigators confirmed a coordinated campaign in which threat actors adopted orphaned packages and injected a two-stage, Tor-routed payload that steals browser data, cryptocurrency wallets, SSH keys, and API keys, then spreads laterally via SSH. The campaign — beginning with the VPN package openconnect-sso and potentially spanning over 200 packages — follows the June 2026 'Atomic Arch' incident in which 400+ packages were similarly hijacked; with roughly 13,000 orphaned packages still in the AUR, the structural attack surface remains wide open. Developer and CI/CD environments that pull AUR packages during builds should treat any recently adopted or newly active packages as untrusted until the adoption freeze is lifted and all affected packages are audited.
Developer and CI/CD environments that pull AUR packages during builds should treat any recently adopted or newly active packages as untrusted until the adoption freeze is lifted and all affected packages are audited.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.