Three supply chain campaigns in one week — 400+ hijacked AUR packages, a nine-year Linux PAM backdoor, and fresh KEV entries for Oracle and Ivanti. The June 2026 lesson: trust itself is the attack surface.
Quick Answer
Week 3 of June 2026 delivered three attacks on trusted infrastructure. First: 400+ Arch Linux AUR packages were hijacked through maintainer account takeover. The rewritten PKGBUILDs deployed a Rust credential stealer, plus an eBPF rootkit on root builds. Verify any AUR package built on or after June 11. Second: Sygnia disclosed that China-nexus Velvet Ant hid backdoored PAM/OpenSSH login components for nearly nine years, harvesting credentials via secret passwords. Deploy file integrity monitoring on PAM, SSH, and sudo now. Third: CISA added CVE-2026-35273 (Oracle PeopleSoft, unauthenticated takeover, due June 15) and CVE-2026-10520 (Ivanti Sentry root RCE in unmanaged state) to the KEV catalog, alongside a critical FortiSandbox RCE. Defender priorities: verify build scripts and login binaries, pin dependencies, enforce mTLS, and automate KEV response.
The Week in Breaches: Trust Is the Attack Surface
June 2026 continues a grim trend: attackers now target the trust chain itself rather than individual software flaws. This week brought three distinct supply chain campaigns. Each one abuses the implicit trust defenders place in familiar tools, maintainers, and update mechanisms. For earlier coverage, see Week 1 and the Week 2 digest. The full-month picture is in the June threat landscape briefing.
1. Arch Linux AUR Hijack: 400+ Packages Weaponized
Over 400 packages in the Arch User Repository were compromised. Attackers took over legitimate maintainer accounts and silently rewrote the build scripts. The malicious build process deployed a Rust-based credential stealer. Run with root privileges, it also installed an eBPF rootkit for kernel-level persistence. The compromised packages kept their names, histories, and maintainer identities. Only the build instructions changed. The official Arch repositories were unaffected.
Defender takeaway: this is not a software vulnerability. It is a trust model vulnerability. Package managers and CI/CD pipelines need to verify build scripts on every update — not just the resulting binaries. Full anatomy in our AUR hijack deep-dive.
2. Velvet Ant: Linux PAM Backdoored for Nearly a Decade
Sygnia researchers disclosed a campaign by a China-nexus group tracked as Velvet Ant. The group spent nearly nine years hidden inside Linux login infrastructure. It deployed no detectable malware. Instead, it replaced core PAM (Pluggable Authentication Modules) and OpenSSH components with backdoored versions.
- Backdoored PAM modules allowed attacker authentication via secret passwords
- Some variants recorded all legitimate credentials as users logged in
- Nine separate backdoor versions were discovered across the network
- Initial access traces date back to 2016
- The targeted network had no direct internet access — attackers staged through internet-facing systems first
Detection challenge: the modifications lived in trusted login binaries themselves. Standard endpoint detection and file integrity monitoring often flagged the changes as legitimate updates. Organizations should continuously verify the integrity of critical system binaries (PAM, SSH, sudo). Watch for anomalous login patterns too — especially credentials used from impossible geographies.
3. CISA KEV: Oracle and Ivanti Entries
CISA added two new entries to its Known Exploited Vulnerabilities catalog this week. Both are actively exploited, and both carry federal remediation deadlines under BOD 26-04:
| CVE | Product | Flaw | Impact | Deadline |
|---|---|---|---|---|
| CVE-2026-35273 | Oracle PeopleSoft PeopleTools | Missing authentication for critical function | Unauthenticated takeover | Added Jun 12 · due Jun 15 |
| CVE-2026-10520 | Ivanti Sentry | OS command injection (unmanaged state) | Unauthenticated root RCE | Per KEV feed |
The Ivanti flaw is exploitable when endpoints are externally reachable without mTLS/EPMM protection. Audit your exposure accordingly. See also our earlier June KEV analysis for the month’s other additions.
4. Fortinet FortiSandbox Critical RCE
Fortinet patched a critical remote code execution flaw in FortiSandbox. Unauthenticated attackers can execute commands via crafted HTTP requests. FortiSandbox sits inside malware analysis pipelines, so a compromise does more than breach a host. It can blind threat detection by controlling the verdicts the SOC relies on. Patch immediately. In the interim, check sandbox verdict logs for anomalies.
Defender Playbook: Hardening Against Supply Chain Attacks
- Verify build integrity: use reproducible builds and diff build scripts between versions — not just binaries
- Monitor critical binaries: run file integrity monitoring on PAM modules, SSH binaries, and sudo configs. Compare baselines against vendor signatures
- Segment access: internet-facing systems must not directly reach critical internal infrastructure. The Velvet Ant staging pattern depends on that bridge
- Pin dependencies: lock package versions and require manual review for updates in CI/CD pipelines
- Track the KEV catalog: subscribe to CISA’s feed and automate patch prioritization for new entries
- Audit mTLS enforcement: for products like Ivanti Sentry, verify external endpoints require mutual TLS or EPMM protection
Frequently Asked Questions
What happened in the Arch Linux AUR hijack?
Attackers took over maintainer accounts for 400+ packages in the Arch User Repository. They rewrote the PKGBUILD scripts to deploy a Rust credential stealer, plus an eBPF rootkit wherever builds ran as root. Package names, versions, and histories stayed identical, so normal updates looked clean. If you built or updated an AUR package on or after June 11, 2026, verify against the affected lists and rotate credentials.
What is the Velvet Ant PAM backdoor?
A China-nexus APT campaign disclosed by Sygnia. The group replaced Linux PAM and OpenSSH components with backdoored versions. The backdoors accepted secret attacker passwords, and some variants recorded every legitimate credential at login. Nine backdoor versions persisted across the network, with initial access traces dating to 2016. They survived because the changes lived inside trusted authentication binaries.
Which CISA KEV entries were added this week?
Two entries. CVE-2026-35273 hits Oracle PeopleSoft Enterprise PeopleTools: missing authentication for a critical function enables unauthenticated takeover. It was added June 12, 2026 with a June 15 remediation deadline. CVE-2026-10520 hits Ivanti Sentry: OS command injection gives unauthenticated root RCE when the appliance sits unmanaged without mTLS/EPMM protection. Both are actively exploited.
Why is a FortiSandbox RCE especially dangerous?
FortiSandbox sits inside malware analysis pipelines. Whoever controls it controls the verdicts your SOC trusts. A compromise can breach the host and silently reclassify malicious samples as clean. Detection goes blind while the appliance appears operational. Patch immediately and review historical verdict logs for anomalies.
{“@context”:”https://schema.org”,”@type”:”FAQPage”,”mainEntity”:[{“@type”:”Question”,”name”:”What happened in the Arch Linux AUR hijack?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Attackers took over maintainer accounts for 400+ packages in the Arch User Repository and rewrote PKGBUILD build scripts to deploy a Rust credential stealer plus an eBPF rootkit on root builds. Names, versions, and histories stayed identical, so normal updates looked clean. Anyone who built or updated an AUR package on or after June 11, 2026 should verify against affected package lists and rotate credentials.”}},{“@type”:”Question”,”name”:”What is the Velvet Ant PAM backdoor?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”A China-nexus APT campaign disclosed by Sygnia in which Linux PAM and OpenSSH components were replaced with backdoored versions accepting secret attacker passwords and recording legitimate credentials at login. Nine backdoor versions persisted since roughly 2016 because the changes lived inside trusted authentication binaries, defeating standard endpoint detection.”}},{“@type”:”Question”,”name”:”Which CISA KEV entries were added this week?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”CVE-2026-35273 (Oracle PeopleSoft Enterprise PeopleTools — missing authentication enabling unauthenticated takeover; added June 12, 2026, due June 15, 2026) and CVE-2026-10520 (Ivanti Sentry — OS command injection giving unauthenticated root RCE in unmanaged state without mTLS/EPMM). Both are actively exploited.”}},{“@type”:”Question”,”name”:”Why is a FortiSandbox RCE especially dangerous?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”FortiSandbox sits inside malware analysis pipelines, so compromise controls the verdicts the SOC trusts. An attacker can breach the host and silently reclassify malicious samples as clean — blinding detection while the appliance appears operational. Patch immediately and review verdict logs for anomalies.”}}]}
References
- Sygnia — Velvet Ant Linux PAM backdoor research
- CISA — Known Exploited Vulnerabilities catalog, June 2026 additions
- Fortinet — FortiSandbox critical security advisory
- Hmmnm — Over 400 Arch Linux AUR Packages Hijacked
- Hmmnm — Weekly Threat Intel June 2026 — Week 1
- Hmmnm — Threat Intel Weekly June 2026 — Week 2
- Hmmnm — CISA KEV June 2026: Android, Palo Alto, Oracle
- Hmmnm — Cybersecurity Threat Landscape June 2026
The supply-chain crisis pattern, distilled
The June supply-chain cluster — AUR hijack, PAM backdoor, and registry incidents — reads as one lesson in three dialects: every layer of the software stack that inherits trust without verifying provenance eventually transfers that trust to an attacker. The package layer inherits trust from names and histories (the AUR and registry entries). The system layer inherits trust from source and signing (the PAM backdoor — a trojanized authentication module planted where distribution integrity was assumed). The remediation pattern is equally unified: provenance verification at every trust-transfer point, diff-review on trust-metadata changes, and execution monitoring as the backstop that catches what verification misses.
The PAM backdoor deserves its own emphasis for defenders: authentication-module compromise is keystroke-grade territory — everything that authenticates through the trojanized module is exposed, including credentials for systems far beyond the compromised host. File-integrity monitoring on authentication paths (PAM modules, NSS libraries, SSH binaries) is the detection that catches this class, and the baseline images for that monitoring are the clean-vendor-image doctrine from the appliance genre applied to the OS layer.
The synthesis for engineering leadership: supply-chain security is no longer a package-manager topic but an operating-system one — the same verification discipline must reach the authentication stack, the boot chain, and the update channels, because attackers demonstrated this quarter that they will use all of them, in whichever order trust is weakest.
From incident response to standing verification
The June crisis also demonstrated the value of standing verification as distinct from incident response: organizations that had pre-built package-diff automation and authentication-path integrity monitoring processed the AUR and PAM events as alert queues, while peers stood up emergency review processes mid-crisis. The difference repeated a pattern this series documents at every scale — the value of controls is realized at incident speed, but it is created at implementation speed, and the two clocks never align for the unprepared.
The standing-verification stack, itemized for reuse: nightly lockfile-diff reports with maintainer-change flags; file-integrity monitoring on authentication and boot paths with vendor-baseline comparison; registry-advisory feeds matched automatically against manifests; and a quarterly tabletop that exercises the full chain — advisory lands, inventory matches, diff reviews, decision, deploy. Four artifacts, none novel, all cheap relative to one incident day, and all currently deployed at the organizations that read supply-chain months as routine and at few others.
That gap — between the documented stack and its adoption — is the honest closing note of the crisis: the sector knows how to prevent June-class events and mostly has not done so, because standing verification competes with roadmap work until the day it competes with incident response. The choice repeats monthly; the incident record merely keeps score.
The stack is documented, the adoption is optional, and the incident record keeps score with monthly precision. The choice is on every roadmap now.
