Thomas Strömberg
KD4UHP - based in Carrboro, NC
#unix #infosec #bikes #carrboro #motorcycles #photography #hamradio
founder & principle eng @ isotope¹³, ex-Director of Security @ Chainguard & Xoogler
After being locked away for 10+ years in the Cloud; it's so refreshing, and frustrating to deal with all of the little things; like filesystems, database replication and locks, replacing fans and NICs, debugging OOMs, and crashing daemons on #FreeBSD, #OmniOS, and #Linux;
I feel like everything moves a little more slowly and sustainably this way; but most of all - I really missed getting lost in the details.
One of my favorite features with #atomdrift's approach to supply-chain attack decomposition is the ability to quickly find other samples using the same techniques by clicking on the #malecule - our custom hash based on a program's behavioral profile. This NPM was uploaded just a few minutes ago, but matches many attacks we've seen throughout the last month.
https://codeberg.org/atomdrift/stng - my wild strings(1) replacement for security engineers has a shiny new release (v1.2.0):
* New arm64 stack-XOR decoder for macOS malware
* Fewer false positives for IPv4 constants
* 66% faster XOR scanning
cleave v1.2.0 is now available! cleave is the successor to malcontent - decomposing a program into a set of MBC/ATT&CK-aligned features useful for security engineers and ML pipelines alike.
The screenshot is how cleave sees an ELF #malware sample that was dropped just yesterday. Using both AST and automated reverse engineering [rizin], cleave executes 50,000+ rules across 75 file formats.
The best part of being a solo-founder is the ability to take guilt-free thinking rides. It gave me the clarity on what I'd like to ship next for #atomdrift - JSON trait context, improved lab interface, and a --second-opinion option for (local but non-deterministic) LLM assistance. Coming to #litmus soon!
Our latest #opensource drop: https://github.com/chainguard-dev/acls-in-yaml
As part of #SOC2 #compliance, we've been using this to run monthly #audit reviews of our ACLs across SaaS platforms: #GCP, #Slack, #Vercel, etc.
acls-in-yaml dumps #ACLs from each platform into a consistent and neutral #YAML format, which makes it easy to visualize change over time.
We use this by committing the result into a #Github repo and getting the PR reviewed by the admins for each system.
PS: ACL change alerts are also awesome!
New blog post outlining some of the #infosec #detection techniques we use with #osquery, specifically against the most interesting new macOS malware of the past year:
https://unfinished.bike/behavioral-detection-of-macos-malware-using-osquery
Most malicious #npm packages steal; #express-timer just deletes your source tree a minute after you install it — and its author fumbled their own online-banking password into the very same tarball; just wow.
It's trivially detectable using existing open-source software too: https://atomdrift.org/discoveries/2026/06/express-timer-self-destruct-wiper/
With #atomdrift - we're detecting a dozen new supply-chain attacks every day; on-par with the commercial vendors. Most are boring, but some are brazen - this attempt at a CDN-distributed #cryptojacker is the latter: https://atomdrift.org/discoveries/2026/06/v018-axios-cdntest-c-is-for-cookie/
New day, new silly malware samples found - this time it's PyPI's turn: https://atomdrift.org/discoveries/2026/06/spadata-roblox-cookie-stickup/