Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIOver 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
Over 400 packages in Arch Linux's Arch User Repository (AUR) were compromised this week through hijacked build scripts that deployed credential-stealing malware. The Rust-based infostealer targets developer secrets and can deploy an eBPF rootkit when executed with root privileges to evade detection.
AI400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
Over 400 packages in Arch Linux's Arch User Repository (AUR) were compromised this week when attackers hijacked them and modified build scripts to deploy credential-stealing malware. The malicious payload is a Rust-based binary designed to harvest developer credentials and secrets, with the capability to deploy an eBPF rootkit when executed with root privileges to evade detection.
AIVerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
China-linked cyber espionage group VerdantBamboo has been observed deploying a BSD variant of the BRICKSTORM backdoor along with PLENET (GRIMBOLT) and AGENTPSD malware to target Linux systems. Volexity attributes this activity to VerdantBamboo, which overlaps with Microsoft's Clay Typhoon threat group. This represents an expansion of the threat actor's capabilities to target BSD and Linux-based ap
