
Hugging Face update, GitHub security improvements, DPRK linked to chald/debug, and more new PolinRider research
This week we discussed:
Update from Hugging Face: Hugging Face published a technical timeline of the OpenAI evaluation agent that breached its production infrastructure between July 9 and July 13, reconstructing over 17,000 attacker actions across the five day window. OpenAI's own follow-up disclosure this week revealed the agent didn't stop at Hugging Face. It accessed accounts on four other services during the intrusion. We dig into why the agent went after the ExploitGym answer key instead of solving the benchmark honestly, and what that says about reward-seeking behavior in autonomous agents.
GitHub ships publish-time malware scanning and holds risky Actions workflows: On July 28, GitHub announced two supply chain security changes on the same day. npm packages are now scanned before they become available for install rather than after, and GitHub Actions will hold workflow runs identified as potentially malicious until a repository collaborator with write access approves them. Both announcements are thin on technical detail, and we talk through what triggers are probably getting flagged and why GitHub and npm have been slow to take on this kind of liability.
Amazon ties DPRK to the chalk and debug compromise: Amazon published research attributing the September 2025 compromise of the debug and chalk npm packages, along with the typo-crypto package first seen in March 2025, to the DPRK threat actor tracked as SAPPHIRE SLEET. We talk about why this link wasn't news to researchers who've been tracking DPRK's tradecraft for a while, and why TeamPCP's loud, public style keeps pulling attention away from the North Korean groups doing far more financial damage.
PolinRider automation causes account takeovers without targeting: New OSM research examined 20 npm and Go packages compromised through PolinRider's automatic credential harvesting rather than a deliberate account takeover. We explain why maintainers infected through fake job interviews and poisoned VS Code tasks ended up publishing malware to packages nobody had specifically targeted, and why that distinction changes how defenders should think about the threat.
Episode resources:
- (report) Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
- (blog) OpenAI Says Its Rogue AI Agent Didn't Just Hack Hugging Face
- (changelog) npm publish-time malware scanning and dual-use metadata
- (changelog) GitHub Actions holds potentially malicious workflows for approval
- (report) Amazon identifies North Korean hacker group behind open-source supply chain attacks
- (blog) Amazon Links Debug and Chalk npm Hijack to North Korea's Sapphire Sleet
- (webpage) typo-crypto
- (podcast) To Catch a Thief: North Korea On Our Payroll
- (blog) PolinRider Caused Dozens of npm and Go Compromises
Information
- Show
- PublishedJuly 30, 2026 at 10:00 PM UTC
- Length42 min
- Season1
- Episode15
- RatingClean