This Week In Security: Arch AUR, Steam Marketplace, WordPress All Face Issues, Taco-Themed Coding, And Mythos Makes National News

Starting on June 11, 2026, the Arch User Repository (AUR) was targeted by malware which rapidly compromised over 1,500 packages. The AUR repository allows for abandoned community packages to be taken over by a new maintainer, which was exploited by the attackers to claim ownership.

Once the packages were adopted by the malicious maintainers, the next part should sound familiar: The package build scripts, which are executed by the Arch yay and paru package managers, were modified to install malicious NPM packages (atomic-lockfile and js-digest) each containing the now-usual suite of infostealer malware targeting browser credentials and tokens, SSH private keys, package repository tokens, cloud compute, AI tokens, and crypto wallets.

The malware once installed uses several tricks to cloak itself by renaming processes, and to install systemd services to restart itself, and leveraging eBPF filtering in the kernel to hide the sockets and processes further. It specifically targets browsers and Electron-based applications, which are basically a light-weight Chromium browser disguised as an application anyway. Slack, Discord, Signal, and many more use the Electron wrapper.

A preliminary analysis of the malware is available, which breaks down the exact behavior in more detail and lists the known targets of the malware.

Initially believed to be “only” a few hundred packages, the compromised list eventually grew to over 1500, and additional packages may still be discovered. On June 14, Phoronix reported that a second wave of compromised packages has been found in the AUR repositories, including NeoVim plugins and multiple browsers. The second set of infected packages were compromised in a similar fashion, but with more heavily obfuscated scripts.

Steam Wallpaper Malware

Kaspersky Labs finds that Steam users have been targeted by malware uploaded via a popular animated wallpaper application, “Wallpaper Engine”.

While Valve normally does an admirable job filtering the Steam store, it looks like an exploit has slipped through in “Wallpaper Engine”. Animated wallpapers can be videos, web pages, or full executables themselves. Obviously, being able to run any program masquerading as wallpaper directly is an excellent vector to install malware, so of course this is what happened.

Using the integrated Steam Workshop, which allows users to share game mods and other game content directly, malicious wallpapers install a wide variety of malware including the usual gamut of infostealers, remote access, residential proxy, key logging, and crypto miners. This makes it one of the rare times installing crypto miners almost makes sense, considering most Steam users likely have better than average video cards.

Once a user is infected, the malware also steals the current Steam login credentials, and several instances attempt to then upload additional infected wallpapers to the Steam Workshop under the compromised users identity, completing the supply chain circle of life.

Continue reading “This Week In Security: Arch AUR, Steam Marketplace, WordPress All Face Issues, Taco-Themed Coding, And Mythos Makes National News”

Come With Me If You Want To Weed: Autonomous Weedinator Robot Back For 2026

The WEEDINATOR agricultural robot is one of the longer-running projects we’ve featured here on Hackaday. We first featured it way back in 2017 for that year’s Hackaday prize, and after a nearly a decade of work on-and-off it has hit a very important milestone: it is now an effective horticultural instrument, as you can see in the latest demo video below.

There have been some big changes over the years. For one, the scope of the project narrowed considerably with the adoption of a commercial tractor as the base, specifically an Iseki 321 . They picked the Iseki after examining several competitors, and it won out because its hydrostatic drive was best able to handle the very low speeds desired. It looks like they’re now focused on cultivation — that is, tearing out weeds mechanically — rather than the flame weeder they started with. The cultivators are of the claw type, and has three claws powered via the tractor’s hydraulics for control in all three axis: X, Y and Z. Of course the project now leverages modern computer vision toolsets, using a combination of OpenCV and YOLO26n running on a Jetson Nano board. The robotics half of the equation is handled on an STM32 Nucleo.

Aside from being one of our longer-running submissions, we have to call out the team for being one of the very few — perhaps the only — to go to the effort of creating a theme song for their project. If you’ve only got a minute to see the robot run, you might as well look at the second video embedded below and give a listen.

While WEEDINATOR has got the most persistence, they’re not the only ones in the garden robot game. We’ve seen projects using everything from concentrated sunlight to precision-applied herbicides to clear unwanted plants over the years.

Continue reading “Come With Me If You Want To Weed: Autonomous Weedinator Robot Back For 2026”

Running Modern Linux On A 68008

Linux developers have been trimming the fluff in recent years, removing support for older processors that hardly anyone uses with a modern kernel anymore. With that said, it’s possible to run the latest kernel on some truly old metal. As a case in point, [Colin Maykish] just got it going on a Motorola 68008!

The rig in question is a Mackerel-68k—a homebrew single-board computer built around Motorola’s famous 68000 CPU line. This version in particular is running a 68008 rated at 8 MHz, though it’s overclocked to 14 MHz for a little more pep, and has just 3.5 MB of RAM. Despite these limitations, the board can run the mainline v7.1-rc6 kernel, booting into userspace and providing a very minimalistic BusyBox shell. Booting is slow, and doing much more than that is impossible without running out of RAM, but it’s an impressive feat nonetheless. [Colin] has also had the 68010 and 68030 chips running the kernel, too.

We’ve previously discussed efforts to bring Linux into the future while leaving old chips behind. Video after the break.

Continue reading “Running Modern Linux On A 68008”