MEDIUMSupply Chain
Global

Atomic Arch npm Campaign Adds Malicious Dependency

·Source: Sonatype (Maven/npm)

Updated:

Executive Summary

Analysis

Sonatype researchers have identified a malicious package campaign, dubbed Atomic Arch, that targets orphaned packages in the Arch User Repository (AUR).

Indicators of Compromise (3)

URL (2)
https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency
https://www.sonatype.com/hubfs/RapidResponse_Templates_Malware%20%284%29.png
Domain (1)
www.sonatype.com
Source Attribution

Originally published by Sonatype (Maven/npm) on Jun 11, 2026.

Related Threats