Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A coordinated supply chain attack compromised more than 400 packages in the Arch Linux User Repository (AUR) and introduced a malicious npm package, delivering credential-stealing malware paired with a kernel-level rootkit that hides itself from standard security tools. Developer workstations and CI/CD build environments are the primary targets, with confirmed exfiltration of GitHub credentials, SSH private keys, HashiCorp Vault tokens, and secrets from Slack, Teams, Discord, and browser stores. Any organization whose developers use Arch Linux or install packages from AUR must assume compromise of all secrets accessible on affected machines and treat full system reinstallation as the minimum remediation threshold.

Author

Tech Jacks Solutions