Don't be afraid of the #rootkit bit of the malicious bonus material that shipped with some #ArchLinux #AUR packages recently , it is not really hard to detect in a generic way.
In the past few months I had been doing some research on #Linux #rootkits and figured out some techniques I hadn't seen implemented before. Since existing tools seemed inadequate for hunting for rootkits in large, diverse environments, I wrote rk-expose which compiles to a smallish (<1MB) static binary. It comes with lots of well-known and some novel rootkit detection techniques – and detects the malware distributed with the "atomic arch" campaign using its "ps-diff" command out of the box.





