• News/
  • https://www.bleepingcomputer.com/news/security/arch-linux-pulls-aur-packages-that-installed-chaos-rat-malware/

Arch Linux pulls AUR packages that installed Chaos RAT malware

BleepingComputer
·
Lawrence Abrams
·
Published Jul 18, 2025
·
Updated

Arch Linux has pulled three malicious packages uploaded to the Arch User Repository (AUR), which were used to install the CHAOS remote access trojan (RAT) on Linux devices. The packages were named "librewolf-fix-bin", "firefox-patch-bin", and "zen-browser-patched-bin," and were uploaded by the same user, "danikpapas," on July 16. The packages were removed two days later by the Arch Linux team after being flagged as malicious by the community. "On the 16th of July, at around 8pm UTC+2, a malicious AUR package was uploaded to the AUR," warned the AUR maintainers. "Two other malicious packages were uploaded by the  same user a few hours later. These packages were installing a script  coming from the same GitHub repository that was identified as a Remote Access Trojan (RAT)." The AUR is a repository where Arch Linux users can publish package build scripts (PKGBUILDs) to automate the process of downloading, building, and installing software that is not included with the operating system. However, like many other package repositories, the AUR has no formal review process for new or updated packages, making it the user's responsibility to review the code and installation scripts before building and installing the package. Although all the packages have now been removed, BleepingComputer found archived copies of all three, indicating that the threat actor began submitting the packages at 18:46 UTC on July 16. Each package, "librewolf-fix-bin", "firefox-patch-bin", and "zen-browser-p...

Read full article

Affected Software

3 affected components
Arch Linux librewolf-fix-bin
Arch Linux firefox-patch-bin
Arch Linux zen-browser-patched-bin
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Arch Linux's decision to remove three malicious packages from its Arch User Repository due to their role in installing Chaos RAT malware.

2

What security implications are discussed in the article?

The article highlights the risks associated with using unverified packages in software repositories, which can lead to malware infections.

3

What malware is referenced in the article?

The malware mentioned in the article is the CHAOS remote access trojan (RAT).

4

What specific packages were removed from the Arch User Repository?

The removed packages are 'librewolf-fix-bin', 'firefox-patch-bin', and 'zen-browser-patched-bin'.

5

Who is affected by this security issue?

Linux users who installed the malicious AUR packages are affected by this security issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203