Introduction
Cybersecurity researchers have discovered a sophisticated supply chain attack targeting Arch Linux users through malicious packages disguised as variants of the Firefox browser.

On July 16, 2025, three infected packages containing Remote Access Trojan (RAT) malware were successfully uploaded to the Arch User Repository (AUR), and were detected and removed by the Arch Linux security team two days later.
Attack Timeline
The security breach began on July 16, 2025, around 8:00 PM UTC+2, when a member of an unknown threat organization uploaded the first malicious package to the AUR.
Within hours, the same user account distributed two additional infected packages, all containing the same malicious payload from a single GitHub repository.
The attack went undetected for approximately 46 hours before the Arch Linux team discovered and addressed the security incident on July 18, 2025 (around 6:00 PM UTC+2).
The timing of this attack is particularly concerning given the widespread use of Arch Linux among developers and security professionals, who often install packages from the AUR.
The attackers demonstrated a deep understanding of the Arch Linux ecosystem by targeting browser-related packages, which typically receive a large number of downloads due to their importance.
The three compromised packages specifically targeted users seeking alternative configurations and browsers to Firefox.
The librewolf-fix-bin package appeared to provide a fix for the privacy-focused LibreWolf browser, while the firefox-patch-bin suggested patches for standard Firefox installations.
The third package, zen-browser-patched-bin, targeted users of the Zen browser, promising enhanced features.
Each package contained scripts to establish persistent remote access on infected systems.
The malware was designed to execute silently during the package installation process, potentially granting the attacker full system access without the user’s knowledge.
Security analysts noted that the RAT implementation employed sophisticated evasion techniques, indicating the involvement of experienced cybercriminals.
This incident highlights the inherent risks of package repositories maintained by the open-source community, even in mature Linux distributions.
News Link:
https://gbhackers.com/hackers-injected-malicious-firefox-packages/

Scan to Follow
Cybersecurity News by Jun Ge
Telling security stories that ordinary people can understand