How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Atomic Arch npm Campaign Adds Malicious Dependency

calendar_today June 11, 2026 person research@sonatype.com (Sonatype Security Research Team) domain sonatype

TL;DR On June 11, 2026, Sonatype researchers uncovered Atomic Arch, a new campaign targeting orphaned packages in the Arch User Repository in which attackers take over legitimate, abandoned AUR projects and modify PKGBUILDS to install a malicious npm package during installation. Analysis of atomic-lockfile, the malicious dependency, found a bundled Linux payload with functionality tied to credential harvesting, stealth, anti-debugging, and potential data exfiltration. On June 12, 2026, a second wave emerged, using Bun-based installation paths in some affected packages rather than npm alone.

open_in_new Read original post