Last Updated: 2026-08-03T16:19:14Z
What’s Happening
A new round of Arch User Repository malware has prompted the disabling of package adoption.
The first package with confirmed malware appears to be openconnect-sso.
User ysf has performed initial analysis of the payloads.
Stage 1: AUR validator.malware (stage 1) · GitHub
Stage 2: AUR validator.malware (stage2 agent linux x86_64) · GitHub
Interestingly, many of the behaviors (especially Tor exfil) look similar to the last campaign.
The AUR team is actively working to remove malicious commits.
New malicious commits were still being discovered through Saturday. The payload appears to be the exact same as the previous samples.
As of Monday, AUR pushes have been disabled entirely.
Actions
It appears that these samples still use Tor as the download source for the second stage. Deny Tor outbound on your network to neuter this attack.
Review the results of the AUR Audit tool and compare with your installed packages.
Indicators
| Value | Type | Description |
|---|---|---|
e73a35b3e75e94746428d1a207703d6335933deadee7d1d9c9d0328df7b9df77 |
SHA256 | Stage 1 Hash |
2d25d2ea313767fae5808164224cf6ad610ab09546d1e5a6f033eedbfd98a281 |
SHA256 | Stage 1 Hash |
06c857c8ca798d50c765b4de39e6c4f272ecb57bc8316a8ed4c0fdf02fb59502 |
SHA256 | Stage 2 Stealer Hash |
p4ayykxcrxfyzrgfbbkazernntjbz43hgclrheguylzd7kijmtce6zqd.onion |
Onion Domain | C2 Download Location |
.service |
String | Systemd Service Name |
.com.apple.telemetry.<random> |
String | LaunchDaemons/LaunchAgents plist |
For Windows (why?) the dropper creates a randomly-named Scheduled Task.
Notes
We are continuing to monitor the situation and develop a useful set of indicators. It’s too early to tell yet how common the identified hashes are.
