We value your privacy

This website or its third-party tools process personal data. You can opt out of the sale of your personal information by clicking on the "Do Not Sell or Share My Personal Information" link.

Do Not Sell or Share My Personal Information

Powered by Visit CookieYes website

Opt-out Preferences

We use third-party cookies that help us analyse how you use this website, store your preferences, and provide the content and advertisements that are relevant to you. However, you can opt out of these cookies by checking "Do Not Sell or Share My Personal Information" and clicking the "Save My Preferences" button. Once you opt out, you can opt in again at any time by unchecking "Do Not Sell or Share My Personal Information" and clicking the "Save My Preferences" button.

Do Not Sell or Share My Personal Information

CancelSave My Preferences

Your opt-out preference has been honored.

Banner closes automatically in s...

Powered by Visit CookieYes website

Twitter LinkedIn Facebook Reddit Email Share

Security Bloggers Network

by Sonatype Security Research Team on June 11, 2026

TL;DR

  • Sonatype researchers uncovered Atomic Arch, a new campaign targeting orphaned packages in the Arch User Repository in which attackers take over legitimate, abandoned AUR projects and modify PKGBUILDS to install a malicious npm package during installation.

  • This is especially concerning because the trusted package itself may not look obviously malicious. The attack hides behind build instructions, downstream dependencies, and existing developer trust.

  • Analysis of atomic-lockfile, the malicious dependency, found a bundled Linux payload with functionality tied to credential harvesting, stealth, anti-debugging, and potential data exfiltration.

  • The bigger lesson: attackers no longer need to create trust from scratch. Sometimes they can inherit it.

Sonatype researchers have identified a malicious package campaign, dubbed Atomic Arch, that targets orphaned packages in the Arch User Repository (AUR).

The post Atomic Arch npm Campaign Adds Malicious Dependency appeared first on 2024 Sonatype Blog.

\\\* This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by [Sonatype Security Research Team](/content/author/0/ "Read other posts by Sonatype Security Research Team"/index.html). Read the original post at: https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency

[June 11, 2026June 11, 2026](/content/2026/06/atomic-arch-npm-campaign-adds-malicious-dependency/ "2:52 pm"/index.html)[Sonatype Security Research Team](/content/author/sonatype-security-research-team/ "Sonatype Security Research Team"/index.html)0 CommentsSonatype Research

Disqus Recommendations

We were unable to load Disqus Recommendations. If you are a moderator please see our troubleshooting guide.

tempest.services.disqus.com

tempest.services.disqus.com is blocked

This page has been blocked by an extension

  • Try disabling your extensions.

ERR_BLOCKED_BY_CLIENT

Reload

This page has been blocked by an extension

Disqus Comments

We were unable to load Disqus. If you are a moderator please see our troubleshooting guide.

Security Boulevard Comment Policy

Comments are moderated

Got it

G

Start the discussion…

Comment

Log in with
or sign up with Disqus or pick a name

Disqus is a discussion network

  • Don't be a jerk or do anything illegal. Everything is easier that way.

Read full terms and conditions

This comment platform is hosted by Disqus, Inc. I authorize Disqus and its affiliates to:

  • Use, sell, and share my information to enable me to use its comment services and for marketing purposes, including cross-context behavioral advertising, as described in our Terms of Service and Privacy Policy, including supplementing that information with other data about me, such as my browsing and location data.
  • Contact me or enable others to contact me by email with offers for goods or services
  • Process any sensitive personal information that I submit in a comment. See our Privacy Policy for more information

Acknowledge I am 18 or older

Favoriting means this is a discussion worth sharing. It gets shared to your followers' Disqus feeds, and gives the creator kudos!

Find More Discussions

Share

  • Tweet this discussion

    • Share this discussion on Facebook
    • Share this discussion via email
    • Copy link to discussion
  • Best

Be the first to comment.

Load more comments

tempest.services.disqus.com

tempest.services.disqus.com is blocked

This page has been blocked by an extension

  • Try disabling your extensions.

ERR_BLOCKED_BY_CLIENT

Reload

This page has been blocked by an extension

Email*


×

Insert/edit link

Close

Enter the destination URL

URL

Link Text

Open link in a new tab

Or link to existing content

Search

No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.

Cancel

Copy link

✓

Thanks for sharing!

Find any service

AddToAny

[More…](/content/2026/06/atomic-arch-npm-campaign-adds-malicious-dependency/#addtoany "Show all"/index.html)

A2A

Notifications

previousnextslideshow

We'd like to show you notifications for the latest news and updates.

AllowCancel