Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

2026-06-13T01:24:11Z4a8edaf7f5f9fc1d1bb095c2185b4004ca7a5d496b6d9391c01c5f109066f6ea
agentjackingai-abusearch-linuxaudiA6','sniper-dzaurbackdoorbitlocker-bypasschina-nexuscredential-theftcryptocurrency-launderingebpf-rootkitgeminigreatxmlinfostealerjdv-botnetjdy-botnetlangflowlanggraphopenclawopensshpamphaaSphishingsmishingsupply-chain

What happened

A cluster of high-impact incidents and vulnerabilities across open-source ecosystems, enterprise software, and AI tooling. Attackers hijacked >400 Arch Linux AUR packages, altering build scripts to install a Rust infostealer that can load an eBPF rootkit when run as root. Long-running backdoors were found in Linux login components (PAM/OpenSSH) attributed to a China-linked group. AI abuse is rising: Google sued a smishing/PhaaS network for weaponizing Gemini; researchers disclosed ‘agentjacking’ and OpenClaw techniques that force AI agents to execute attacker code or exfiltrate secrets. Active

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4a8edaf7f5f9fc1d1bb095c2185b4004ca7a5d496b6d9391c01c5f109066f6ea
Enrichment time
2026-06-13T01:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.