Incident
Published 2026-09-25
Verified 2026-09-28

LuaRocks.org (Sep 2026): rockspec bytecode RCE exploited Jul–Aug — API keys, 2FA secrets, sessions revoked; upgrade client ≥3.12

LuaRocks.org official incident notice (Security Incident, September 2026) states CISA coordinated a report on 25 September 2026 of remote code execution in the rockspec upload path: rockspecs are Lua files loaded in a restricted environment, but the loader accepted precompiled LuaJIT bytecode that could escape the sandbox. Fixed 26 September 2026 (text-only rockspec load). Forensic review found exploitation on 9 July, 7 August (three malicious packages published: bcrcewon, 7e0b94029db0, 7e0b9402f9c8 — removed), and hundreds of automated upload-API attempts 16–20 August. Site rebuilt on a new server; every credential the old host held revoked. Exposed (assumed): usernames, emails, bcrypt password hashes, API keys, 2FA secrets, GitHub link tokens, session/IP data, third-party server credentials. No evidence existing packages were modified (git mirror from 8 July compared). Users: create new API key, re-login, change password (+ elsewhere reused), re-enrol 2FA, upgrade LuaRocks client to 3.12+ (≤3.11.1 on LuaJIT/Lua 5.1 can run precompiled bytecode from a malicious server). Treat machines that installed the three attacker packages as compromised. Primary: luarocks.org incident notice.

Product
LuaRocks.org package registry; LuaRocks client (LuaJIT / Lua 5.1 bytecode path)
Versions
Server-side rockspec bytecode load fixed 26 Sep 2026. Client: upgrade to LuaRocks 3.12 or newer (3.11.1 and older on LuaJIT/Lua 5.1 accept precompiled bytecode from a server).
Exploited in Australia?
unknown
Patch to
Create a new LuaRocks API key; end sessions / log in again; change password and any reused passwords; re-enable 2FA; upgrade LuaRocks client to ≥3.12; remove/never install bcrcewon, 7e0b94029db0, 7e0b9402f9c8 and treat hosts that did as compromised; package maintainers review recent versions via the Security Audit page

Primary: LuaRocks.org — Security Incident, September 2026 (vendor primary) · Vendor: LuaRocks.org (official incident notice) · LuaRocks.org — registry home (API keys / Security Audit)

breaches cloud identity