New AUR Attack Prompts Adoption Lock

Last Updated: 2026-08-03T16:19:14Z

What’s Happening

A new round of Arch User Repository malware has prompted the disabling of package adoption.

The first package with confirmed malware appears to be openconnect-sso.

User ysf has performed initial analysis of the payloads.

Stage 1: AUR validator.malware (stage 1) · GitHub

Stage 2: AUR validator.malware (stage2 agent linux x86_64) · GitHub

Interestingly, many of the behaviors (especially Tor exfil) look similar to the last campaign.

The AUR team is actively working to remove malicious commits.

New malicious commits were still being discovered through Saturday. The payload appears to be the exact same as the previous samples.

As of Monday, AUR pushes have been disabled entirely.

Actions

It appears that these samples still use Tor as the download source for the second stage. Deny Tor outbound on your network to neuter this attack.

Review the results of the AUR Audit tool and compare with your installed packages.

Indicators

Value Type Description
e73a35b3e75e94746428d1a207703d6335933deadee7d1d9c9d0328df7b9df77 SHA256 Stage 1 Hash
2d25d2ea313767fae5808164224cf6ad610ab09546d1e5a6f033eedbfd98a281 SHA256 Stage 1 Hash
06c857c8ca798d50c765b4de39e6c4f272ecb57bc8316a8ed4c0fdf02fb59502 SHA256 Stage 2 Stealer Hash
p4ayykxcrxfyzrgfbbkazernntjbz43hgclrheguylzd7kijmtce6zqd.onion Onion Domain C2 Download Location
.service String Systemd Service Name
.com.apple.telemetry.<random> String LaunchDaemons/LaunchAgents plist

For Windows (why?) the dropper creates a randomly-named Scheduled Task.

Notes

We are continuing to monitor the situation and develop a useful set of indicators. It’s too early to tell yet how common the identified hashes are.

1 Like