Arch Linux has taken a temporary measure to disable the adoption of Arch User Repository (AUR) packages in response to a recent surge in malicious takeovers of existing packages. This decision was announced by contributor Robin Candau on the distribution's mailing list, citing the need for a temporary solution until a more permanent fix can be implemented.
Malicious Package Adoptions
The situation is a result of a campaign that began on July 29, with the package 'openconnect-sso' being the first to be affected. According to a technical analysis conducted by the Independent Federated Intelligence Network (IFIN), this campaign bears similarities to a previous one that hit AUR in June, which distributed a Linux rootkit and info-stealer malware to unsuspecting users through over 400 packages.
Two-Stage Infection
The latest attack involves a two-stage infection process. The first stage acts as a loader, while the second stage is a Linux x86_64 payload that has been described as stealer malware with remote administration (RAT) and SSH worm features. The first-stage loader evades detection by checking for debuggers, sandboxes, virtual machines, and CI/CD environments before installing systemd services and cron jobs to ensure persistence.
It then downloads and launches a Tor client disguised as dbus-daemon to retrieve the second-stage payload from an '.onion' server. The second stage is a Rust-based infostealer that targets browser credentials, cryptocurrency wallets, password manager data, cloud and developer secrets, AI service API keys, SSH keys, and messaging platform tokens.
Remote Command Execution and Lateral Spread
The stealer malware provides the attacker with remote command execution over an encrypted Tor channel and can spread laterally by using stolen SSH keys to copy and execute itself on other systems. A Reddit user tracking the campaign alleges that it has expanded to over 200 AUR packages, either through compromised maintainer accounts or by adopting orphaned packages.
Some of the fairly popular AUR packages that have been allegedly compromised include boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server. However, the compromised status of these packages has not been independently confirmed, and a list of all 200 AUR packages believed to be malicious has not been made available as of publication.
Security Measures
In light of this situation, it is essential for users to exercise caution when using AUR packages. The Arch Linux project has advised users to report any suspicious adoption events or commits that haven't been dealt with yet and to stay vigilant. As the situation is temporary, the project will send a follow-up once a solution is found.
In the meantime, users can take steps to protect themselves from similar attacks by being cautious when adopting packages and by monitoring their systems for any suspicious activity. It is also crucial for the community to come together to find a solution to this issue and to prevent such attacks from happening in the future.
Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Source: BleepingComputer