We value your privacy
This website or its third-party tools process personal data. You can opt out of the sale of your personal information by clicking on the "Do Not Sell or Share My Personal Information" link.
Do Not Sell or Share My Personal Information
Powered by Visit CookieYes website
Opt-out Preferences
We use third-party cookies that help us analyse how you use this website, store your preferences, and provide the content and advertisements that are relevant to you. However, you can opt out of these cookies by checking "Do Not Sell or Share My Personal Information" and clicking the "Save My Preferences" button. Once you opt out, you can opt in again at any time by unchecking "Do Not Sell or Share My Personal Information" and clicking the "Save My Preferences" button.
Do Not Sell or Share My Personal Information
CancelSave My Preferences
Your opt-out preference has been honored.
Banner closes automatically in s...
Powered by Visit CookieYes website
Twitter LinkedIn Facebook Reddit Email Share
by Sonatype Security Research Team on June 11, 2026
TL;DR
Sonatype researchers uncovered Atomic Arch, a new campaign targeting orphaned packages in the Arch User Repository in which attackers take over legitimate, abandoned AUR projects and modify PKGBUILDS to install a malicious npm package during installation.
This is especially concerning because the trusted package itself may not look obviously malicious. The attack hides behind build instructions, downstream dependencies, and existing developer trust.
Analysis of atomic-lockfile, the malicious dependency, found a bundled Linux payload with functionality tied to credential harvesting, stealth, anti-debugging, and potential data exfiltration.
The bigger lesson: attackers no longer need to create trust from scratch. Sometimes they can inherit it.
Sonatype researchers have identified a malicious package campaign, dubbed Atomic Arch, that targets orphaned packages in the Arch User Repository (AUR).
The post Atomic Arch npm Campaign Adds Malicious Dependency appeared first on 2024 Sonatype Blog.
\\\* This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by [Sonatype Security Research Team](/content/author/0/ "Read other posts by Sonatype Security Research Team"/index.html). Read the original post at: https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency
[June 11, 2026June 11, 2026](/content/2026/06/atomic-arch-npm-campaign-adds-malicious-dependency/ "2:52 pm"/index.html)[Sonatype Security Research Team](/content/author/sonatype-security-research-team/ "Sonatype Security Research Team"/index.html)0 CommentsSonatype Research
- ← Google can be liable for false AI Overviews, court rules
- BSides Seattle 2026 – Signed Twice, Broken Never: The Rise Of Hybrid PKI →
Disqus Recommendations
We were unable to load Disqus Recommendations. If you are a moderator please see our troubleshooting guide.
tempest.services.disqus.com
tempest.services.disqus.com is blocked
This page has been blocked by an extension
- Try disabling your extensions.
ERR_BLOCKED_BY_CLIENT
Reload
This page has been blocked by an extension
Disqus Comments
We were unable to load Disqus. If you are a moderator please see our troubleshooting guide.
Security Boulevard Comment Policy
Comments are moderated
Got it
G
Start the discussion…
Comment
Log in with
or sign up with Disqus or pick a name
Disqus is a discussion network
- Don't be a jerk or do anything illegal. Everything is easier that way.
Read full terms and conditions
This comment platform is hosted by Disqus, Inc. I authorize Disqus and its affiliates to:
- Use, sell, and share my information to enable me to use its comment services and for marketing purposes, including cross-context behavioral advertising, as described in our Terms of Service and Privacy Policy, including supplementing that information with other data about me, such as my browsing and location data.
- Contact me or enable others to contact me by email with offers for goods or services
- Process any sensitive personal information that I submit in a comment. See our Privacy Policy for more information
Acknowledge I am 18 or older
Discussion Favorited!
Favoriting means this is a discussion worth sharing. It gets shared to your followers' Disqus feeds, and gives the creator kudos!
Tweet this discussion
- Share this discussion on Facebook
- Share this discussion via email
- Copy link to discussion
Be the first to comment.
tempest.services.disqus.com
tempest.services.disqus.com is blocked
This page has been blocked by an extension
- Try disabling your extensions.
ERR_BLOCKED_BY_CLIENT
Reload
This page has been blocked by an extension
Email*
Insert/edit link
Close
Enter the destination URL
URL
Link Text
Open link in a new tab
Or link to existing content
Search
No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.
Cancel
Copy link
✓
Thanks for sharing!
Find any service
[More…](/content/2026/06/atomic-arch-npm-campaign-adds-malicious-dependency/#addtoany "Show all"/index.html)
A2A
Notifications
previousnextslideshow
We'd like to show you notifications for the latest news and updates.
AllowCancel