SANS Stormcast Monday, June 15th, 2026: Arch Linux Malicious User Packages; Splunk Vuln and Exploit; Exploiting AI Coding Agents
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 755 Ratings
🗓️ 15 June 2026
⏱️ 7 minutes
🔗️ Recording | Apple Podcasts | RSS
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, June 15th, |
| 0:07.6 | 2006 edition of the Sands International Storm Center's Stormcast. |
| 0:12.6 | My name is Johannes Ulrich, recorded day from Jacksonville, Florida. |
| 0:17.6 | And this episode is brought you by the Sands.edu credit certificate program in cyber defense operations. |
| 0:25.1 | Well, and sadly, yet again, we have to start the week with a supply chain compromise. |
| 0:30.7 | And this one is a little bit different. |
| 0:32.3 | It actually affects a popular Linux distribution, Arch Linux. |
| 0:41.1 | Now, Arch Linux has this system. They're calling Arch User Repository or AUR. This is a place where users can essentially create their |
| 0:48.5 | own packages. So these are not official packages that are delivered as part of ARCH Linux. |
| 0:55.1 | And then, of course, with a lot of these open source project, there's always a risk of |
| 0:59.4 | packages being abandoned and then no longer being maintained. So to solve this ARCH user repository |
| 1:06.6 | has a system where a package can be marked as abandoned, no longer maintained, |
| 1:12.3 | and then any developer can step up and basically take on ownership of this particular |
| 1:17.3 | repository. |
| 1:18.3 | Now, many of them, of course, are hardly used. |
| 1:21.3 | But what happened here with Atomic Arch, this campaign that Sonatipe here wrote about, |
| 1:26.8 | is that attackers picked abandoned packages |
| 1:29.9 | that were somewhat popular, and then instead of modifying actually the code in the package, |
| 1:36.4 | what they did is that they added a code to the post-install script in the package. |
| 1:44.9 | And that's sort of then how they basically added the malicious code. |
| 1:50.0 | They just had an NPM install atomic lock file, then also minimists and chalk that they |
| 1:57.2 | installed. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

