# Risky Bulletin: Arch Linux supply chain attack hits 1,900 packages Page: https://stenobird.com/podcast/risky-bulletin-5423259/risky-bulletin-arch-linux-supply-chain-attack-hits-1-900-packages Text version: https://stenobird.com/podcast/risky-bulletin-5423259/risky-bulletin-arch-linux-supply-chain-attack-hits-1-900-packages.md Podcast: [Risky Bulletin](https://stenobird.com/podcast/risky-bulletin-5423259) Published: 2026-06-15T05:53:18+00:00 Episode link: https://risky.biz/RBNEWS577/ Audio file: https://dts.podtrac.com/redirect.mp3/media3.risky.biz/RBNEWS577.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/risky-bulletin-5423259/episodes/risky-bulletin-arch-linux-supply-chain-attack-hits-1-900-packages Duration seconds: 674 ## Resource Almost 2,000 Arch Linux packages have been infected with malware in a supply chain attack, FISA surveillance powers expire for the first time since 2008, the FBI takes down a Chinese phishing service, and a major supply chain attack hits the WordPress ecosystem. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/risky-bulletin-5423259/episodes/risky-bulletin-arch-linux-supply-chain-attack-hits-1-900-packages/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/risky-bulletin-5423259/risky-bulletin-arch-linux-supply-chain-attack-hits-1-900-packages.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.