The OpenSourceMalware Show

OpenSourceMalware

When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day. Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target. OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more. https://opensourcemalware.com/

  1. -6 дн.

    Ransomeware arrests, crypto heist, Mac and Baileys malware, DPRK's A/B testing

    This week we talked about:  ShinyHunters and KillSec arrests: Dutch police arrested Pepijn van der Stap, a long-time ShinyHunters member known as Umbreon, on September 16, less than a year after he finished a prison sentence for earlier hacking. His arrest followed a power struggle with the group's 16-year-old leader over who controls its infrastructure. Separately, police arrested three suspected members of the KillSec ransomware group. The group is linked to roughly 1,000 attacks and used AI to build its infrastructure and identify victims.Bitget crypto heist: Suspected North Korean hackers stole $351.6 million from the hot and warm wallets of crypto exchange Bitget. Customer accounts still showed full balances after the funds were drained. Incident response firm SlowMist attributes the initial access to a zero-day in an unnamed security product.Signed Mac malware posing as Claude Desktop: A lookalike Claude Desktop site is serving a signed macOS installer hosted on GitHub. It appears to be the real app with a padded payload added. Because it's signed, macOS installs it without warning, and the file is about four times the size of the real installer.Baileys campaign update: The number of malicious npm packages abusing the Baileys WhatsApp library now tops 100. Most only inflate follower counts for WhatsApp channels, so the direct risk is low. Some have also served as a base for other attacks, including WhatsApp-based C2.PolinRider A/B testing: DPRK's PolinRider campaign is changing its fake font trick to slip past detections that rely on a single file name. The fa-solid-400.woff2 payload has been renamed to 500, 900, and 300 and moved deep into legitimate folders. Most recently it was given a .llf extension that has nothing to do with fonts.We're hiring: OpenSourceMalware is looking for a part-time malware researcher with software supply chain experience.Resources (blog) Dutch Police Arrest 'Reformed' Hacker in Shiny Hunters Investigation(blog) Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers(blog) Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise(feed) OpenSourceMalware threat reports tagged #baileys(blog) 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent(blog) PolinRider is A/B Testing its Way Past Your Detections

    Ransomeware arrests, crypto heist, Mac and Baileys malware, DPRK's A/B testing
  2. 24 сент.

    ShinyHunters attacks FBI, new WeaselBiscuit malware, Contagious Interview research, and dev FAQs

    This week we discussed:  ShinyHunters vs. the FBI and Cl0p: ShinyHunters claims it stole data from an FBI jobs website through a PeopleSoft zero-day, and it is threatening to leak that data unless the FBI retracts a May FLASH tied to the Instructure Canvas breach. We cover why aging enterprise monoliths like PeopleSoft and WebLogic are such attractive targets. We also get into the group's escalating public feud with ransomware crew Cl0p.A correction on WhatsApp Baileys attacks: Malicious Baileys typosquats aren't targeting WhatsApp payments, as we said last week. We explain what these packages actually do and how threat actors make money from them.WeaselBiscuit: A new, stripped-down, self-contained malware family derived from BeaverTail and OtterCookie has turned up in 16 npm packages so far. We share the latest on attribution, what the malware is designed to steal, and why its minimal design helps it slip past detection.FBI joint advisory on Contagious Interview: The FBI and international partners issued a joint warning about the DPRK IT workers scam and Contagious Interview (under the name WaterPlum), with figures on infected devices and stolen cryptocurrency. We discuss what the advisory leaves out. We also explain why its finding of shared infrastructure with the IT workers scam matters for researchers and defenders.Atlassian's Contagious Interview research: Atlassian published research on Contagious Interview activity across Bitbucket, GitLab, and GitHub, along with the actions it has taken on its own platform. We discuss what the report reveals about the campaign beyond GitHub and how platforms differ in responding to researcher reports.Developer questions from TikTok: Our viral TikTok explainer on the VS Code tasks autorun technique drew a set of recurring questions from developers. We answer them, including "How this malware gets onto developer machines", "Whether signed commits or switching editors would stop it", "Why antivirus misses it", and "How researchers know North Korea is behind it."Episode resources: (X) ShinyHunters statement on the FBI(webpage) ShinyHunters - Cyber Criminal Group Attacks Learning Management System(blog) ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach(feed) Baileys threat reports(blog) WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials(PDF) North Korean "WaterPlum," commonly referred to as "Contagious Interview," Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe(blog) From fake interviews to malicious repositories - Disrupting Contagious Interview(TikTok) How the VS Code tasks autorun attack works

    ShinyHunters attacks FBI, new WeaselBiscuit malware, Contagious Interview research, and dev FAQs
  3. 16 сент.

    OpenAI allegedly attacked RubyGems, PyPI typosquats contain prompt injection, and new Mac malware

    This week we talked about:  New research alleges OpenAI agents were behind the RubyGems attack. A report from independent researchers argues an OpenAI agent swarm is responsible for the GemStuffer campaign, which uploaded hundreds of spammy packages to RubyGems in May. Truffle Security's Luke Marshall followed up with the vulnerability the agents used (a CDN misconfiguration) that could expose other users' RubyGems API keys. OpenAI has yet to comment on either report."lurves-agent" campaign is typosquats PyPI packages to target AI users. The campaign name comes from a string the malware's own AI-generated code self-attributed inside a bash script, suggesting the threat actor used an AI agent to write it without reviewing the output. Across five or six packages typosquatting OpenAI and other AI framework names, the payload is a short info-stealer, and the surrounding comments function as a prompt injection aimed at any AI reviewing the code.A typosquatted Claude site is distributing signed Mac malware. claude-desktop.com delivers a signed DMG instead of the real Claude desktop app, taking advantage of the fact that official install instructions for tools like Claude and OpenAI's CLI have changed repeatedly over the past year, making people less careful about where they install from. Resources:  (report) OpenAI agents carried out an undisclosed cyber-attack on RubyGems(blog) We discovered a Ruby account takeover; Rogue OpenAI Agents exploited it 2 months prior(threat feed) lurves-agent records on OpenSourceMalware(LinkedIn) Three Injections and a Rootkit: How Lurves PyPI Typosquat Attacks...

    OpenAI allegedly attacked RubyGems, PyPI typosquats contain prompt injection, and new Mac malware
  4. 27 авг.

    TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts

    This week we talked about:  TeamPCP arrests — Australian Federal Police and the FBI arrested Ruben Thomson (21) and Louis Gaebler (23) in Perth on TeamPCP-related charges. The arrests align with the OpenSourceMalware team's longstanding assessment that TeamPCP was a very small operation, effectively one or two people, despite the scale of its attacks. Krebs' reporting details the OPSEC failures (reused usernames and passwords, prolific unredacted social media activity) that led to their identification, and despite the technical complexity of the attacks, the financial payout was reportedly modest (around $20K). Jenn and Paul discuss what this could mean for other overlapping threat groups like Lapsus$ and ShinyHunters.PolinRider's persistence outlasts partial remediation — A look at how DPRK's PolinRider campaign continues to reinfect developers who believed they'd already cleaned up. When a developer only removes the malicious payload files but not the underlying persistence mechanism (like a vscode-task.json trigger) or the RAT running on their machine, DPRK can push new payloads that ride along on the developer's own legitimate package publishes. Paul and Jenn cover what's changed in the kill chain: a new NullReceiver-branded payload, a persistence technique that overwrites the npm CLI binary itself so simply removing payloads from repos isn't sufficient, and an expanding target list of JavaScript/TypeScript file types the malware will inject into. They close on why disclosing an infection to collaborators matters, since silent individual cleanup doesn't stop reinfection through shared repos and contributors.Episode resources TeamPCP: (news) Two WA men charged after investigation into alleged cybercrime(official) Two WA men charged following AFP FBI WAPF disruption alleged global cybercrime syndicate(news) Two Alleged 'TeamPCP' Hackers Arrested in AustraliaPolinRider: (blog) PolinRider npm case study of a DPRK attack(blog) Developer guide to getting over PolinRider

    TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts
  5. 20 авг.

    Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads

    This week we talked about:  Rust arrayref compromise tied to DPRK infrastructure: A compromised maintainer account published malicious versions of the arrayref crate, along with internment and append-only-vec, adding a typosquatted build dependency that downloaded and executed a remote binary at compile time. arrayref alone has more than 245 million lifetime downloads and sits in roughly three quarters of all Rust environments. Wiz Research has tied the campaign's infrastructure, including a shared C2 endpoint pattern and overlapping IP ranges, to the same DPRK actor behind the Mastra and Axios npm compromises. StubMaker spreads from RubyGems to npm: What started as a RubyGems typosquatting campaign targeting bundler, i18n, rake, and activesupport turned out to share byte-for-byte identical payloads with a separate 40 package npm typosquatting cluster targeting axios, chalk, commander, lodash, react, and typescript. Both campaigns deliver the same 22MB Rust loader and embedded Go infostealer, confirmed by matching SHA-256 hashes, giving one threat actor two independent paths into any organization running both a Ruby and a Node stack. There's also evidence that this campaign hit the PowerShell ecosystem. DIY binary payloads make a comeback: Paul has seen a sharp increase over the last two weeks in software supply chain attacks bundling compiled binaries (C++, Rust, Go) instead of sticking to the interpreted languages that dominate malicious open source. The theory: less experienced threat actors are following old malware-writing conventions, possibly with an assist from AI coding agents, without realizing that shipping a binary inside an npm or RubyGems package is itself one of the biggest red flags an analyst can ask for. PolinRider reinfection wave using NullReceiver: We're still continuously seeing developers talking about getting reinfected with PolinRider. This latest iteration swaps out EtherHiding for NullReceiver as its stage two hiding method, and Paul and Jenn walk through why victims keep getting reinfected even after they think they've cleaned up: the malware lives on the developer's machine, not just in the repo, and it can commit to Git history without leaving an obvious trail. Episode Resources: (blog) Supply chain attack on arrayref(blog) Rust Supply Chain Attack on arrayref, Significant Overlap with DPRK Campaigns(webpage) arrayref crate threat report(blog) StubMaker RubyGems Campaign Delivers a Windows Infostealer(blog) Windows Infostealer Hits npm and Ruby

    Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads
  6. 13 авг.

    Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft

    This week we talked about:  Hacker Summer Camp trends. Jenn and Paul share observations from Black Hat, DEF CON, and BSides Las Vegas last week, including a maturing AI security conversation that has shifted to focus on where AI still falls short, particularly the last mile of precision and finesse that still requires a human to verify. They also discuss the emerging challenge of identifying malicious AI skills, where the natural language format makes static analysis much harder than it is for traditional package ecosystems. And they revisit the recurring gap between security teams who understand binary malware and incident response and those who understand the open source software supply chain.GitHub revokes npm bypass-2FA token privileges. GitHub announced it is closing a gap that let npm granular access tokens configured to bypass two factor authentication perform sensitive account, org, and package management actions, a change Jenn and Paul say is overdue but underexplained.DPRK's NullReceiver technique keeps spreading. Following up on last week's episode, Paul shares that the number of packages using the NullReceiver technique, tied to the PolinRider campaign, has grown well past the seven originally confirmed, and that DPRK's use of crypto payments for infrastructure like VPN services could offer new tracking opportunities for defenders.Episode resources: (blog) Restricting npm bypass-2FA granular access tokens(blog) NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding

    Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft
  7. 7 авг.

    New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation

    This week we talked about: New npm worm hits Keyv and cacheable. Jared Wray's GitHub account was compromised on Tuesday, and threat actors used it to publish a worm based on the open-sourced Mini Shai-Hulud malware. The worm spread to over 400 packages, with ServiceTitan alone losing 100 packages, and it searches developer machines and CI runners for credentials across GitHub, npm, AWS, Kubernetes, Vault, Azure, Google Cloud, Terraform, Docker, and Slack before exfiltrating them. We also talk about how this got caught within minutes despite GitHub's recent claims of proactive pre-publication malware scanning.The WEL1DROPPER campaign is flooding npm with AI slopsquatted packages. Over the past 72 hours, more than a thousand malicious packages have been published to npm as part of a campaign we're calling WEL1DROPPER. It doesn't rely on install scripts at all, executing instead when a package is imported, and we believe it's loosely connected to the earlier Moika campaign based on shared tradecraft. We dig into why attribution to Russian threat actors is complicated given the campaign also targets Russian and Belarusian financial institutions.DPRK is using a new C2 technique we're calling NullReceiver. We found DPRK-linked malware hiding its C2 IP address inside the recipient address of a completely empty Ethereum transaction, an evolution of the EtherHiding technique that fixes its biggest weakness: a fixed, publicly known destination address. We've confirmed at least 10 packages using this new technique so far.Episode Resources: (blog) New npm Worm Hits 400+ Packages Including Keyv, Cachable(blog) Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages(blog) NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding

    New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation

Об этом подкасте

When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day. Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target. OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more. https://opensourcemalware.com/

Вам может также понравиться