The OpenSourceMalware Show
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.
Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.
OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more.
https://opensourcemalware.com/
The OpenSourceMalware Show
Latest Episodes
Live from Strasbourg & Underground Economy
Jenn and Paul also mark OpenSourceMalware's first anniversary, now tracking close to 200,000 verified threats and over 100,000 IOCs. We also discuss:Mini Shai-Hulud payload resurfaces on npm. A payload from May's Mini Shai-Hu...
TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts
This week we talked about: TeamPCP arrests — Australian Federal Police and the FBI arrested Ruben Thomson (21) and Louis Gaebler (23) in Perth on TeamPCP-related charges. The arrests align with the OpenSourceMalware tea...
Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads
This week we talked about: Rust arrayref compromise tied to DPRK infrastructure: A compromised maintainer account published malicious versions of the arrayref crate, along with internment and append-only-vec, adding a typosqu...
Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft
This week we talked about: Hacker Summer Camp trends. Jenn and Paul share observations from Black Hat, DEF CON, and BSides Las Vegas last week, including a maturing AI security conversation that has shifted to foc...
New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation
This week we talked about:New npm worm hits Keyv and cacheable. Jared Wray's GitHub account was compromised on Tuesday, and threat actors used it to publish a worm based on the open-sourced Mini Shai-Hulud malware. The worm s...
Contributors
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Open Source Security
Josh Bressers
Future of Threat Intelligence
Team CymruAbsolute AppSec
Ken Johnson and Seth Law
Coffee, Chaos and ProdSec
Cameron Walters and Kurt Hendle