Over 400 Arch Linux AUR Packages Compromised to Distribute Rootkit and Infostealer
More than 400 packages in the Arch User Repository (AUR) were compromised by a threat actor spoofing a trusted maintainer, delivering a Linux rootkit with eBPF capabilities and an infostealer targeting developer secrets via a malicious npm dependency. No insured entity losses, specific commercial asset damage, or confirmed corporate breach with insurance implications have been reported.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. The event is a notable open-source software supply-chain compromise but, based on available reporting, affects a community-maintained repository used primarily by individual developers and power users rather than large insured enterprises. There is no evidence of confirmed corporate breaches, insurance claims activity, or quantified insured losses. The event is relevant for cyber underwriters monitoring supply-chain attack patterns and extortion/credential-theft trends but currently sits at low insured materiality until enterprise impact emerges.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialLloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts