Arch Linux has pulled three malicious packages uploaded to the Arch User Repository (AUR), which were used to install the CHAOS remote access trojan (RAT) on Linux devices. The packages were named "librewolf-fix-bin", "firefox-patch-bin", and "zen-browser-patched-bin," and were uploaded by the same user, "danikpapas," on July 16. The packages were removed two days later by the Arch Linux team after being flagged as malicious by the community. "On the 16th of July, at around 8pm UTC+2, a malicious AUR package was uploaded to the AUR," warned the AUR maintainers. "Two other malicious packages were uploaded by the same user a few hours later. These packages were installing a script coming from the same GitHub repository that was identified as a Remote Access Trojan (RAT)." The AUR is a repository where Arch Linux users can publish package build scripts (PKGBUILDs) to automate the process of downloading, building, and installing software that is not included with the operating system. However, like many other package repositories, the AUR has no formal review process for new or updated packages, making it the user's responsibility to review the code and installation scripts before building and installing the package. Although all the packages have now been removed, BleepingComputer found archived copies of all three, indicating that the threat actor began submitting the packages at 18:46 UTC on July 16. Each package, "librewolf-fix-bin", "firefox-patch-bin", and "zen-browser-p...
Arch Linux pulls AUR packages that installed Chaos RAT malware
BleepingComputer
·Lawrence Abrams
·Published Jul 18, 2025
·Updated
Affected Software
3 affected components
Arch Linux librewolf-fix-bin
Arch Linux firefox-patch-bin
Arch Linux zen-browser-patched-bin
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Arch Linux's decision to remove three malicious packages from its Arch User Repository due to their role in installing Chaos RAT malware.
2
What security implications are discussed in the article?
The article highlights the risks associated with using unverified packages in software repositories, which can lead to malware infections.
3
What malware is referenced in the article?
The malware mentioned in the article is the CHAOS remote access trojan (RAT).
4
What specific packages were removed from the Arch User Repository?
The removed packages are 'librewolf-fix-bin', 'firefox-patch-bin', and 'zen-browser-patched-bin'.
5
Who is affected by this security issue?
Linux users who installed the malicious AUR packages are affected by this security issue.