We value your privacy

This website or its third-party tools process personal data. You can opt out of the sale of your personal information by clicking on the "Do Not Sell or Share My Personal Information" link.

Do Not Sell or Share My Personal Information

Powered by [Visit CookieYes website](https://www.cookieyes.com/product/cookie-consent/?ref=cypbcyb&utm_source=cookie-banner&utm_medium=fl-branding)

Opt-out Preferences

We use third-party cookies that help us analyse how you use this website, store your preferences, and provide the content and advertisements that are relevant to you. However, you can opt out of these cookies by checking "Do Not Sell or Share My Personal Information" and clicking the "Save My Preferences" button. Once you opt out, you can opt in again at any time by unchecking "Do Not Sell or Share My Personal Information" and clicking the "Save My Preferences" button.

Do Not Sell or Share My Personal Information

CancelSave My Preferences

Your opt-out preference has been honored.

Banner closes automatically in  s...

Powered by [Visit CookieYes website](https://www.cookieyes.com/product/cookie-consent/?ref=cypbcyb&utm_source=cookie-banner&utm_medium=sl-branding)

[Twitter](/#twitter "Twitter") [LinkedIn](/#linkedin "LinkedIn") [Facebook](/#facebook "Facebook") [Reddit](/#reddit "Reddit") [Email](/#email "Email") [Share](https://www.addtoany.com/share#url=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F06%2Fatomic-arch-npm-campaign-adds-malicious-dependency%2F&title=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency%20-%20Security%20Boulevard)

[Security Bloggers Network](/content/category/sbn/index.html)

[by Sonatype Security Research Team on June 11, 2026](/content/author/sonatype-security-research-team/index.html)

## TL;DR

- Sonatype researchers uncovered Atomic Arch, a new campaign targeting orphaned packages in the Arch User Repository in which attackers take over legitimate, abandoned AUR projects and modify PKGBUILDS to install a malicious npm package during installation.

- This is especially concerning because the trusted package itself may not look obviously malicious. The attack hides behind build instructions, downstream dependencies, and existing developer trust.

- Analysis of atomic-lockfile, the malicious dependency, found a bundled Linux payload with functionality tied to credential harvesting, stealth, anti-debugging, and potential data exfiltration.

- The bigger lesson: attackers no longer need to create trust from scratch. Sometimes they can inherit it.

Sonatype researchers have identified a malicious package campaign, dubbed Atomic Arch, that targets orphaned packages in the Arch User Repository (AUR).

The post [Atomic Arch npm Campaign Adds Malicious Dependency](https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency) appeared first on [2024 Sonatype Blog](https://www.sonatype.com/blog).

\\*\\*\\* This is a Security Bloggers Network syndicated blog from [2024 Sonatype Blog](https://www.sonatype.com/blog) authored by [Sonatype Security Research Team](/content/author/0/ "Read other posts by Sonatype Security Research Team"/index.html). Read the original post at: [https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency](https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency)

[June 11, 2026June 11, 2026](/content/2026/06/atomic-arch-npm-campaign-adds-malicious-dependency/ "2:52 pm"/index.html)[Sonatype Security Research Team](/content/author/sonatype-security-research-team/ "Sonatype Security Research Team"/index.html)[0 Comments](/content/2026/06/atomic-arch-npm-campaign-adds-malicious-dependency/#disqus_thread/index.html)[Sonatype Research](/content/tag/sonatype-research/index.html)

- [← Google can be liable for false AI Overviews, court rules](/content/2026/06/google-can-be-liable-for-false-ai-overviews-court-rules/index.html)
- [BSides Seattle 2026 – Signed Twice, Broken Never: The Rise Of Hybrid PKI →](/content/2026/06/bsides-seattle-2026-signed-twice-broken-never-the-rise-of-hybrid-pki/index.html)

Disqus Recommendations

We were unable to load Disqus Recommendations. If you are a moderator please see our [troubleshooting guide](https://docs.disqus.com/help/83/).

tempest.services.disqus.com

# tempest.services.disqus.com is blocked

This page has been blocked by an extension

- Try disabling your extensions.

ERR\_BLOCKED\_BY\_CLIENT

Reload

This page has been blocked by an extension

Disqus Comments

We were unable to load Disqus. If you are a moderator please see our [troubleshooting guide](https://docs.disqus.com/help/83/).

## Security Boulevard Comment Policy

Comments are moderated

Got it

G

Start the discussion…

Comment

###### Log in with

###### or sign up with Disqus  or pick a name

### Disqus is a discussion network

- Don't be a jerk or do anything illegal. Everything is easier that way.

[Read full terms and conditions](https://docs.disqus.com/kb/terms-and-policies/)

This comment platform is hosted by Disqus, Inc. I authorize Disqus and its affiliates to:

- Use, sell, and share my information to enable me to use its comment services and for marketing purposes, including cross-context behavioral advertising, as described in our [Terms of Service](https://help.disqus.com/customer/portal/articles/466260-terms-of-service) and [Privacy Policy](https://disqus.com/privacy-policy), including supplementing that information with other data about me, such as my browsing and location data.
- Contact me or enable others to contact me by email with offers for goods or services
- Process any sensitive personal information that I submit in a comment. See our [Privacy Policy](https://disqus.com/privacy-policy) for more information

Acknowledge I am 18 or older

- [Favorite this discussion](https://disqus.com/embed/comments/?base=default&f=security-boulevard-1&t_i=2103724%20https%3A%2F%2Fwww.sonatype.com%2Fblog%2Fatomic-arch-npm-campaign-adds-malicious-dependency&t_u=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F06%2Fatomic-arch-npm-campaign-adds-malicious-dependency%2F&t_e=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&t_d=%0A%09%09%09%09Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency%09%09%09&t_t=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&s_o=default# "Favorite this discussion")

- ## Discussion Favorited!

Favoriting means this is a discussion worth sharing. It gets shared to your followers' Disqus feeds, and gives the creator kudos!

[Find More Discussions](https://disqus.com/home/?utm_source=disqus_embed&utm_content=recommend_btn)

[Share](https://disqus.com/embed/comments/?base=default&f=security-boulevard-1&t_i=2103724%20https%3A%2F%2Fwww.sonatype.com%2Fblog%2Fatomic-arch-npm-campaign-adds-malicious-dependency&t_u=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F06%2Fatomic-arch-npm-campaign-adds-malicious-dependency%2F&t_e=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&t_d=%0A%09%09%09%09Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency%09%09%09&t_t=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&s_o=default#)

- Tweet this discussion
  - Share this discussion on Facebook
  - Share this discussion via email
  - Copy link to discussion

- [Best](https://disqus.com/embed/comments/?base=default&f=security-boulevard-1&t_i=2103724%20https%3A%2F%2Fwww.sonatype.com%2Fblog%2Fatomic-arch-npm-campaign-adds-malicious-dependency&t_u=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F06%2Fatomic-arch-npm-campaign-adds-malicious-dependency%2F&t_e=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&t_d=%0A%09%09%09%09Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency%09%09%09&t_t=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&s_o=default#)
  - [Newest](https://disqus.com/embed/comments/?base=default&f=security-boulevard-1&t_i=2103724%20https%3A%2F%2Fwww.sonatype.com%2Fblog%2Fatomic-arch-npm-campaign-adds-malicious-dependency&t_u=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F06%2Fatomic-arch-npm-campaign-adds-malicious-dependency%2F&t_e=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&t_d=%0A%09%09%09%09Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency%09%09%09&t_t=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&s_o=default#)
  - [Oldest](https://disqus.com/embed/comments/?base=default&f=security-boulevard-1&t_i=2103724%20https%3A%2F%2Fwww.sonatype.com%2Fblog%2Fatomic-arch-npm-campaign-adds-malicious-dependency&t_u=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F06%2Fatomic-arch-npm-campaign-adds-malicious-dependency%2F&t_e=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&t_d=%0A%09%09%09%09Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency%09%09%09&t_t=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&s_o=default#)

Be the first to comment.

[Load more comments](https://disqus.com/embed/comments/?base=default&f=security-boulevard-1&t_i=2103724%20https%3A%2F%2Fwww.sonatype.com%2Fblog%2Fatomic-arch-npm-campaign-adds-malicious-dependency&t_u=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F06%2Fatomic-arch-npm-campaign-adds-malicious-dependency%2F&t_e=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&t_d=%0A%09%09%09%09Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency%09%09%09&t_t=Atomic%20Arch%20npm%20Campaign%20Adds%20Malicious%20Dependency&s_o=default#)

tempest.services.disqus.com

# tempest.services.disqus.com is blocked

This page has been blocked by an extension

- Try disabling your extensions.

ERR\_BLOCKED\_BY\_CLIENT

Reload

This page has been blocked by an extension

Email\*

* * *

[×](/content/2026/06/atomic-arch-npm-campaign-adds-malicious-dependency/#/index.html)

# Insert/edit link

Close

Enter the destination URL

URL

Link Text

Open link in a new tab

Or link to existing content

Search

_No search term specified. Showing recent items._ _Search or use up and down arrow keys to select an item._

Cancel

Copy link

✓

Thanks for sharing!

Find any service

[AddToAny](https://www.addtoany.com/ "Share Buttons")

[More…](/content/2026/06/atomic-arch-npm-campaign-adds-malicious-dependency/#addtoany "Show all"/index.html)

A2A

Notifications

previousnextslideshow

We'd like to show you notifications for the latest news and updates.

AllowCancel
