Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
2026-06-13T01:24:11Z•4a8edaf7f5f9fc1d1bb095c2185b4004ca7a5d496b6d9391c01c5f109066f6ea
agentjackingai-abusearch-linuxaudiA6','sniper-dzaurbackdoorbitlocker-bypasschina-nexuscredential-theftcryptocurrency-launderingebpf-rootkitgeminigreatxmlinfostealerjdv-botnetjdy-botnetlangflowlanggraphopenclawopensshpamphaaSphishingsmishingsupply-chain
What happened
A cluster of high-impact incidents and vulnerabilities across open-source ecosystems, enterprise software, and AI tooling. Attackers hijacked >400 Arch Linux AUR packages, altering build scripts to install a Rust infostealer that can load an eBPF rootkit when run as root. Long-running backdoors were found in Linux login components (PAM/OpenSSH) attributed to a China-linked group. AI abuse is rising: Google sued a smishing/PhaaS network for weaponizing Gemini; researchers disclosed ‘agentjacking’ and OpenClaw techniques that force AI agents to execute attacker code or exfiltrate secrets. Active
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 4a8edaf7f5f9fc1d1bb095c2185b4004ca7a5d496b6d9391c01c5f109066f6ea
- Enrichment time
- 2026-06-13T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.