A free add-on you grabbed for Arch Linux may have quietly stolen your passwords and the saved logins your apps use. Between about June 11 and 14, 2026, attackers slipped malware into hundreds of packages in the Arch User Repository, the community store where Arch users get extra software the main store does not carry. Security firm Sonatype named the attack Atomic Arch.
The attack abused a normal feature, not a hack. The store lets any user upload the short build instructions that tell your computer how to set up a program. When a maintainer walks away, anyone can take over the package and rewrite those instructions. People who later install or update it then run the new code. The attackers grabbed abandoned packages that still had real, trusting users.
What the malware steals
The virus goes straight for your logins. It grabs saved browser passwords, the keys and tokens that let your computer reach code sites and cloud accounts without a password, and your sign-ins for Slack, Discord, and Teams.
With full control of the computer it could hide and survive a reboot. Developers get hit hardest, since those logins can open a whole company's private code. Early reports counted more than 400 hijacked packages. The total later climbed toward 1,500.
What to do now
Arch reacted fast. It removed the bad changes, banned the attackers' accounts, and briefly froze sign-ups, updates, and package takeovers. The main Arch store was never touched, so none of this matters if you do not run Arch or if you skip community add-ons. But if you installed one in that June window, treat it as serious.
Researchers say to assume the computer is compromised, rebuild it clean, and change every password and login used on it.


