ClosedLow impactAI Refreshed

Over 400 Arch Linux AUR Packages Compromised to Distribute Rootkit and Infostealer

Occurred 12 Jun 2026·Detected 18 Jun 2026·
Global - Arch Linux AUR is a community-maintained online package repository with no geographic boundary2 reportsEnded 29 Jun 2026
CyberPropertyCyberCasualty & Liability

More than 400 packages in the Arch User Repository (AUR) were compromised by a threat actor spoofing a trusted maintainer, delivering a Linux rootkit with eBPF capabilities and an infostealer targeting developer secrets via a malicious npm dependency. No insured entity losses, specific commercial asset damage, or confirmed corporate breach with insurance implications have been reported.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Low impact. The event is a notable open-source software supply-chain compromise but, based on available reporting, affects a community-maintained repository used primarily by individual developers and power users rather than large insured enterprises. There is no evidence of confirmed corporate breaches, insurance claims activity, or quantified insured losses. The event is relevant for cyber underwriters monitoring supply-chain attack patterns and extortion/credential-theft trends but currently sits at low insured materiality until enterprise impact emerges.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts