INTEL_REPORT
LWN.net (kernel & development security) · published 6/19/2026, 2:40:59 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
[$] AURpocalypse now: a look at the recent AUR attacks The Arch User Repository (AUR) has been subjected to a sustained attack recently. The attacker, or attackers, have spun up a series of new accounts then used them to adopt orphaned packages and push malicious updates that would install malware on users' systems. It is unclear how many users were compromised in the attack, but the maintainers were playing Whac-A-Mole for several days to respond to each newly compromised p…
https://lwn.net/Articles/1077619
sha256:b1ce0992f3161b91487034eb1fb32ae68d44624ed76d6f966477e240135b88e5
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.