Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Arc Linux draws more package that installs chaos rat malware
    Security

    Arc Linux draws more package that installs chaos rat malware

    PineapplesUpdateBy PineapplesUpdateJuly 20, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Arc Linux draws more package that installs chaos rat malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Arc Linux draws more package that installs chaos rat malware

    Arc Linux has drawn three malicious packages uploaded on the Arc user repository (AUR), used to install Caous Remote Access Trojan (RAT) on Linux devices.

    The packages were named “Libravolf Fix-Bin”, “Firefox-Patch-Bin”, and “Zen-Buruser-Pitted-Bin”, and uploaded by the same user, “Danikpapas,” on 16 July.

    The package was removed two days later by the Arc Linux team after being marked by the community as malicious.

    “On July 16, at around 8pm UTC+2, a malicious Aur package was uploaded on AUR,” Aur warned maintenance,

    “Two other malicious packages were uploaded by the same user a few hours later. These packages were installing a script coming from the same Github repository that was identified as remote access Trojan (RAT).”

    Maladial
    Maladial
    Source: Bleepingcomputer

    Aur is a repository where arch Linux user can publish the process of downloading, construction and installing the packgbuilds, which is not included with the operating system.

    However, like many other package repository, AUR has no formal review process for new or updated packages, allowing it to review the code and installation script before you create and install the package.

    Although all the packages have now been removed, the Bleeping Computer found the stored copies of the three, indicating that the danger actor started submitting the package on 18:46 UTC on 16 July.

    Each package, “Librewolf-FIX-bin,Firefox-patch-bin“, And “Zen-Buruser-Pachade-Bin“All included a source entry in the PKGBuild file, called” called “Patch“It pointed to a github repository under the control of the attacker:

    When buildpkg is processed, this repository is cloned and considered as part of the patching and building process of the package. However, instead of having a valid patch, the Github repository contains malicious code that was executed during the build or installation phase.

    This github repository has been removed since then, and .git repository is no longer available for analysis.

    However, a Reddit account today began to respond to various arch linux threads on the platform, which promotes these packages on AUR. The comments were posted by an account that seems passive in the years and possibly compromised to spread malicious package.

    Hardcore user reddit Quickly found the comments suspect, one of them uploaded one of the components WirstotalWhich finds it as a linux malware called chaos rat.

    The Caos rat is an open-source remote access trojan (rat) for Windows and Linux that can be used to upload and download files, execute the command and open a reverse shell. Finally, danger actors have complete access to an infected device.

    Once installed, the malware is repeatedly connected to a command and control (C2) server, where it waits to execute the command. In this campaign, the C2 server was located at 130.162 (.) 225 (.) 47: 8080.

    Malware is usually used in cryptocurrency mining campaigns, but it can also be used to cut credentials, steal data or cyber.

    Due to the severity of malware, whoever accidentally installed these packages, should immediately investigate a suspected “Systemd-Initd” executable for the appearance on their computer, which may be located in a /TMP folder. If found, it should be removed.

    The Arc Linux team removed all three packages till 18 July at UTC+2 at around 6 pm.

    “We strongly encourage users who have taken necessary measures to remove one of these packages from their system and to ensure that they were not compromising,” the Arc Linux team warned.


    Knowledgeable

    Include emerging hazards in real time – before they affect your business.

    Learn how cloud detection and response (CDR) gives security teams the required edge in this practical, no-nonsense guide.

    Arc chaos draws installs Linux Malware package Rat
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHere’s what i did to get my data back
    Next Article Nintendo Switch 2 Welcome Tour Review: A Curiosity that must be really free
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    These 7 Linux commands are obsolete so don’t use them – here’s why

    January 14, 2026
    Startups

    I tried the new Linux Mint 22.3 – it’s a masterclass in polish and quality of life improvements

    January 12, 2026
    Startups

    The 6 Linux distros I expect to rule in 2026 – and why

    January 6, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.