Attackers compromised 469 packages in the AUR repository

A mass compromise of packages in the AUR (Arch User Repository), used in Arch Linux for distributing applications from third-party developers, has been reported. Attackers gained control over 469 packages and were able to inject malicious code to steal passwords and access keys from user systems. Among other things, the malicious code was integrated into the ALVR package supplied through AUR, which is popular among computer gaming enthusiasts.

The attackers took over orphaned packages that had no maintainers. They used the name of the last maintainer but a different email, then added one commit and published an update. The commit added 'npm' to the PKGBUILD dependency list and inserted a line into the post_install block of the install.sh script to install several NPM packages. The installed NPM packages included one or more popular legitimate packages and the atomic-lockfile package, which contained hidden malware. The installation of NPM packages was performed in all compromised projects, even if they didn’t use JavaScript and NPM.

Once activated, the malware established itself in the system as a systemd service with a random name and camouflaged itself as kernel traffic. When run with root privileges, the service was created at the system level (/etc/systemd/system) and further activated a rootkit running at the kernel level. When executed with user privileges, it was launched under the user's name (~/.config/systemd/user). The malware scanned for and sent out external server VPN, Docker, Podman, and SSH keys and credentials, as well as confidential data extracted from the browser, shell command history, cryptocurrency wallet keys, access tokens for Slack, Microsoft Teams, Discord, GitHub, NPM, and Vault.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster