The OpenSourceMalware Show
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.
Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.
OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more.
https://opensourcemalware.com/
The OpenSourceMalware Show
Mastra compromise, agentjacking research, busting malware myths
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Mastra Package Compromise: Threat actors hijacked the entire Mastra npm organization (116 packages) after a maintainer was targeted with a ClickFix-style attack that stole his credentials. Rather than injecting malware directly into Mastra packages, attackers pre-staged a typosquatted package called 'easy-day-js' and added it as a dependency across the org. The malware differs from the structurally similar Axios attack in one notable way: it targets browser extensions, including password managers (LastPass, Bitwarden, Dashlane, 1Password) and MFA tools, with Zapier among the more unusual targets.
Agent Jacking and MCP Server Security: A Cloud Security Alliance paper describes a concept called "agentjacking", where attackers inject malicious instructions into Sentry error events, which AI coding agents then retrieve via MCP and execute with the developer's own elevated permissions. This pattern isn't new: weaponizing an agent's privileged access against its owner was a core mechanic of the 2025 S1ngularity attack. What the paper describes is sophisticated prompt injection through an MCP server that fails to sanitize third-party data before passing it to the agent. Its conclusion that EDR can't catch this misses the point, because EDR can't catch most open source malware since the traffic and signals are indistinguishable from normal software development activity.
Malware Myths: We bust four myths making the rounds in the AppSec community. First, that open source malware only lives two to three days: typosquatting and dependency confusion packages routinely survive for weeks or months, and NPM's inconsistent takedown practices make it worse. Second, that npm install scripts are going away: they're not, they are becoming opt-in by default. Third, that package firewalls and cooldowns will eliminate 99% of risk: they won't, for the same reason the lifespan myth is wrong. Fourth, that threat actor attribution doesn't matter: it does, because knowing who compromised you tells you what persistence mechanisms and next steps to look for during incident response.
Episode Resources
We're back. It's Thursday, Thursday, June 18th. I can't believe how quickly this year has gone by. When I set up the stream on what was it Monday or Tuesday, our like little backlog of topics to talk about this week was empty. And I thought, you know, I shouldn't say anything, but I'm going to say it because I don't believe words can make things actually happen. So I was like, you know, it's kind of quiet this week, but I'm sure we'll find something to talk about. Lo and behold, uh, we have something to talk about. And that is the mastra or maestra, however you pronounce it, compromise. Um, we got a few other things on the list, but before we jump in, anything you want to chat about, Paul?
Paul McCartyUh I'm making progress in wiring my office. So I'm hoping that next week, if not next week, I'll be able to record this in my new office. But if not that week, then the week after that. So getting there. Exciting. Very exciting. The Southern Hemisphere headquarters. Southern headquarters Southern Hemisphere headquarters for OSM.
Jenn GileWe'll soon have electricity.
Paul McCartyI'll put a sign up and everything. There's a sticker already, but yeah.
Jenn GileOkay. Well, you know, progress. Um, up here, up up in the the almost the Great White North, uh, school is finally up for the year. I've got a kid out of school, and so now we're kind of properly getting into summer. And gosh, I really wish I could have a summer vacation. But you and I will be in Vegas in what a couple months, less than two months. We'll be there for B-Sides and DEF CON and actually Black Hat as well. So if anybody is going to be there, let us know. We'd love to meet up. Um, who knows if we'll do a happy hour or what the case will be, but you know, coffee, probably lots of water. I don't know. Vegas in August is not my favorite place to be, but it is a fun week.
Paul McCartyI uh I despise Vegas, right? I despise it. But that week, I just I love that week so much. I just get so stoked for that week that I don't care it's in Vegas. It could be in the ninth ring of hell. Well, kind of sort of the same thing. It kind of is could be could be in the 10th ring of hell, and I would still love that week. It's just such a dope week. I just see so many people, you know, the absolute abset guys, and just ah, it's just such a great week, man.
Jenn GileIt is a great week. Okay, on to the meat of things. Um, two days ago, my time, one day ago, your time, uh, we saw a large account takeover in progress. Um, threat actors hijacked the entirety of the Mastra organization, which is 116 packages. And um, very similar to what we saw a couple months ago with the Axios compromise, they didn't actually put the malware in any of the Mastra packages. What they did is they pre-staged a um typosquatted package, an easy easy node.js, easy something.js. Now I can't remember what it is.
Paul McCartyEasy easy day.js.
Jenn GileEasy day.js. Um, so like what we see with a lot of malware, they copied an existing legitimate package, kept everything, and just gave it a snap your name. So they staged it with no malware. And then once they executed their takeover on Mastra, all they had to do was uh add this as a new dependency for all those packages. Et voila, you have an info stealer uh in your packages. Um a lot of vendors have covered what happened with this. Um it is almost uh stage for stage, step for step, the same as the Axios attack, uh, including the initial compromise of the account came through a social engineering, uh very targeted uh spear phishing type thing where the maintainer clicked something that, you know, click fix style, kind of a hey, there's something wrong with your microphone. Oh, I figured it out. You can click this. We saw almost the same thing happen with Axios. Um, Paul, you did a really deep dive on it. I'll share the link uh to the blog that you published. I think it's a really great analysis because um you went deep into the similarities between the two attacks, a little bit about the potential threat actor, which we will say anyone who's saying they know who this is or a little skeptical, we don't have a confirmed um attribution. And then uh what it's targeting, I think is really interesting. So have at it. I'll stop talking.
Paul McCartyMe too. Um listen, first and foremost, there's a lot of other great write-ups from Step Security and Akito and a bunch of other companies, and mad respect to them, right? Um, this was an opportunity for me to do to go deep, like I used to do all the time before I, you know, was building a startup and a business and you know, all these things that we're doing now, right? But so it was nice, it was a blast from the past for me to go super deep on something. But um, yeah, so a couple things. First, um, I didn't know that the actual um the compromise was was happened the way you said it, because I know there was a couple there's contemporaneous, like there was a couple of people that were talking on Twitter about so my source is somebody with the company.
Jenn GileThere's a very good um, well, not very good, it could be better, but there's a pretty decent um retrospective incident report on it on their um GitHub issues from someone who's with the company. I didn't look up who it was, um, but this person said specifically that it was an employee account. Um, that what had happened is I'm gonna read this. Uh, the maintainer is a current active maestro employee. He was compromised via a social phishing attack, a compromised linked out LinkedIn account, reached out to him as well as maintainers of other prominent TypeScript open source packages. He was on a call, clicked a suspicious link, and then um there's a an X post linked in here that says this is the same attack vector as other open source maintainers have reported. And so uh yeah, it was very, very similar to what we saw with Axios.
Paul McCartyYeah, it does sound very, very similar. Um, I think thanks for filling that blank for me. I had seen I had read some of the Twitter posts from other people that have been targeted, uh, you know, in the same time frame. I hadn't seen that specific thing. So um because you know why? Because I went way deep on the malware. So uh in all those other write-ups, I I didn't really see a complete burn down of the malware. Um, and I really wanted to do that because as I started looking at this, and I I went really deep on the plain Crypto.js package, which is what compromised, which was the malicious component that they added to the threat actors added to uh Axios. I went really deep on that one, and so I had all my analyses from that, and then I had all my analyses from this new one, and I could compare them. And the malware, unlike the rest of it, the infrastructure, so basically where they hosted it, like all and I go into a lot of that in my blog, so I'm not gonna go over every single thing again. But basically, from an infrastructure perspective, this looks and feels exactly like Axios.
Jenn GileUm, so they um the well and their mistake here, honestly, it could have been a lot worse. But from what I can see, the way that they handled the publishing, because these uh packages normally come with attestations, and um, there were some tells that meant it was caught extraordinarily quickly. We heard from a friend at AWS that he caught it uh or they caught it within what 30 seconds or two minutes or something really fast.
Paul McCartyRight. Yeah, I mean, I think that the yeah, it was caught really quickly, and you know, and as we see these changes in the NPM ecosystem that you and I've talked about in other episodes, we'll start to see account takeover compromises go down, right? And the post-install, uh, you know, uh this does use post-install scripts. Um, and and so I think bad guys know that you know an NPM 12 is coming and they're trying to. I'm seeing like this week, I'm seeing just this huge onslaught of of new stuff, you know, bad guys trying to get things in before that goes away. But the reality is that most people aren't gonna upgrade to npm 12 right away, anyhow. But I digress. Um yeah, sorry, I got you off track.
Jenn GileTell us about your analysis.
Paul McCartyNo, it's okay. Um, yeah, so from an infrastructure perspective, this looks very similar to um the Axios attack, but when you get in the malware, the malware is different. Um, and it's a two-stage uh uh payload, and the um this Axios, sorry, this um uh payload here in the Mastra campaign is really focused on stealing browser extensions, which Axios was not. Um and so um I went to the trouble of enumerating all the browser extensions uh which are listed in the the blog post. There's 166 of them, I think. And what's interesting about this is they're focusing on the crypto wallet stuff, which we always see, right? So whenever somebody's looking for browser extensions, they always look for crypto stuff. But in addition to that, they're looking for some stuff that's not crypto. So, like roughly 20% of the um browser extensions they're looking for are not crypto wallet extensions. Instead, there's things like LastPass and OnePassword and Dashlane browser extensions, which those three alone, most of us are running one of those three, right? Because those are the big three LastPass, Dashlane, and one password, right? Oh, Bitwarden, too.
Jenn GileSo there's the Yeah, they got all the biggies there, right?
Paul McCartyThe top four password manager extensions, they they're looking for all three of those. They're X-filling all sorry, all four of those. Um, and and a bunch of others too, as well. There's like ones from Deloitte and all kinds of stuff. They're also X-filling a couple of browser-based MFA tools. Um, and uh in the last one, which I think was interesting, was Zapier.
Jenn GileI know. I really want to talk about why you think they're interested in Zapier because like one of these things is not like the other. Uh Zapier is you know used to send uh basically between things that don't have integration. So like your website doesn't have a HubSpot integration, you use Zapier in the middle, and you can pull information back and forth. Why do you think that they targeted Zapier?
Paul McCartyWell, my only guess, and that's all it is, is just a guess, is that you know they're looking to um you know to pivot into other platforms that you've used Zapier to integrate to, right? Because you have to give Zapier authentication um after all these things that you're you know, plugging into to go and do the automation that Zapier is gonna do. And it makes sense to go and and pull it. Um now you would think ostensibly, if they're X-filling it, if they're stealing it, then they have a way to use it, right? Um, which is the expectation. You don't steal stuff, you don't make your X fill package larger unless you have to. Um, you know, I guess the counter-argument is just grab everything you can and make the X fill package as big as possible. Because this is a smash and grab kind of thing, but anyhow.
Jenn GileBut if you know people are getting better about rotating credentials, like if you're not prepared to use it immediately, then it's kind of silly.
Paul McCartyYeah, I mean, you know, then you've got the team PCP thing where they're just sitting on this massive, by the way, I've got something interesting about team PCP too as well. Um, they're sitting on this massive cache of tokens, which are aging poorly for them, right? So people are rotating those, and so every day that goes by, now obviously somebody would make the argument that you know a lot of people don't know that their tokens from team PCP were stolen, and so they're not, you know, they're not um they're not rotating them, which is true, but a lot of people are, and so every day that goes by, team PCP and others like DPRK lose that. Now, I here's the other thing. I wonder, I just I thought this in bed last night as I was going to sleep. I thought I wonder if DPRK is like, hey, listen, you know, this whole crypto wallet stealing thing is going well for us, but it would be nice if we, you know, the boss is really pushing our KPIs we gotta diversify in the Lazus Group Q1 meeting, they really pushed us to increase our capacity. You're killing me over here. And what about if we if we get into to uh initial access broking? You know, basically selling all this stuff that we don't want, right? If it we find it and we ex-fill it, we being TPRK, I'm pretending like I'm the threat actor here. Um, you know, what if we just on sell it? Um now the funny thing about the the IAB marketplace is the more stuff that's out there, the more legitimate stuff that's out there, it drives down the prices, just like any other supply and demand, right? So if you look at the dark web, any kind of credential that there's a lot of and and legitimate examples of drives the price down, with a few exceptions. However, if your uh if the if the access that you're selling is the freshest and the best, then you're always gonna get a premium, right? And I think that because DPRK isn't out there tweeting every gosh darn second, you know, their stuff is probably a little bit fresher than maybe other other thread actors. Holds it better. Say that again, sorry.
Jenn GileOh, it just it holds its value better, yeah.
Paul McCartyPerhaps, yeah. So anyway, I think that was the most interesting thing to come out of Mass Show. Um, sorry, Mass Draw. Um uh was was that, yeah.
Jenn GileYeah. Well, I think that's an interesting segue into one of the other things I have on our show notes. I saw a paper published on the Cloud Security Alliances site earlier this week. And um, I'm gonna say the paper itself isn't like earth-shattering, uh like crazy stuff. But um, the reason I want to talk about it is because we're seeing both um registries and defenders starting to close gaps that are making it harder. And like actually, ironically, I think you and I talked like last week or the week before about how we hadn't seen a social engineering uh generated account takeover in a while and it happened this week. But you know, it's getting harder, and the trend that we've been seeing is because things are getting more firmed up, uh, attackers are more likely to attack the machine pipe. You know, they're trying to get into the the sorry machine path, they're trying to get into the pipeline instead of you know scamming a developer. Well, they're gonna continue to do things along that vibe as we, you know, implement cooldown periods, as we get better at identifying account takeovers, they're gonna look for other means. We've been saying this all spring. And so, what I do think is worth talking about with this paper is it's specifically talking about the possibility of threat actors using your uh integrations with AI agents to get malware to you. And so they're trying to label it as agent jacking. Um, you know, every vendor loves to coin a term. Uh, sure, why not? I think what they've described is really just sophisticated prompt injection. Um, but what they talk about is they take advantage of uh a tool called Sentry, they send it some bogus logs that have uh some malicious payload in there. Uh when the developer goes to say, oh, you know, Sentry's got this uh incident or whatever the right word is to say. Um, you know, I need to research this, I'll just ingest the logs into Claude and figure out how to fix this. Well, the logs come in through an MPCP server, which that in itself I think is like okay, fine. There's lots of ways you can get logs from A to B. It doesn't have to be through an MCP server. But the point is the logs with the malicious payload get handed over to Claude or whatever agent. And then uh much like what we saw last year with the NX Singularity attack, where the agents were weaponized to um scrape for credentials, that's the exact same thing that we're seeing here. So, long story short, I'm not sure that this paper is all that interesting, but it does illustrate what it would look like to take the human mostly out of the equation, which is what attackers are going to increasingly want to do. Yeah, I mean, I think and I'm gonna share that because I know I'm being really vague about it, but I don't really want to promote this vendor because I think it's a little vendor-y.
Paul McCartySo well, that's where I was going with this because you know I was gonna, I'm gonna go, I'm the ranting, rampaging, spicy jerk face that I am. Um, yeah, I mean to me, this read like this is a um PR release from the company, and it turns out it's actually a CSA cloud security, which I'm a member of. I don't know if I'm a paying member or not, but you know, it's just it sounds it felt kind of gross and vendory to me. But um, and like you, I think that what they're describing and them calling it agent jacking, I think ultimately a lot of this just comes down to behavior that I see when people build MCP servers, which is they they built them a year and a half ago, two years ago, really, really quickly. And they just when you look at MCP servers, you see basically a smorgasborg of the OWASP top 10, you know, all encapsulated in many ways.
SPEAKER_01It's like how many mistakes can we make with one technology? Right? Let's put it all in one place.
Paul McCartyThe over provisioning and the exposure of credentials and you know, just every like all these things in one thing. So it's not surprising to see that it's taking advantage of um you know the MCP server, the century MC MCP servers, um uh to do you know to do its bidding. Um, and I guess that's not surprising to me. I also want to mention, and this is something I mentioned to you, is that Sentry, like I've been seeing this in in my malware, you know, analysis for a couple, well, maybe not a couple years, but it's been a while, it's been over a year for sure. Um, yeah, yeah, probably a couple years, where DPRK in particular, like as soon as I see, like if I see two things, Jenna, if I see a file like index.js is obfuscated and I see and I start looking at it, and I see the first thing it imports is is um the centuryio library uh dbrk. Like it's just you know, I mean, those those two little calling card right there, right? And any other any other you know, researcher listening right now probably thinking the same thing, laughing, but they've been using sentry for ages to ex-fill um uh their stolen goods, and it makes a lot of sense because it's you know it's we needed to coin a new term, like living off the SAS or living off the vendor, whatever, you know, like like an alternative off the land, yeah. Uh yeah, yeah. Because you're you're hiding in normal sentry traffic, right? It looks legit. Um, so you know, it makes sense to use it. And sure enough, it's the first thing, pretty much the first thing. Well, they they'll import a couple things, FS and HTTP and then they import sentry. So anyhow.
Jenn GileYeah, and I think uh another perhaps uh I'm gonna call it a criticism of this paper, is it talks about why your security processes can't catch this agent jacking, and it's very SecOps focused, it's very focused on EDR. And um while they're not wrong, the same can also be said for most malicious open source because the threat actors are very good at hiding their activity in benign looking things. You know, they'll spin up a versal endpoint or uh they'll use a uh Bitcoin wallet or something like that. So uh what we do need to like work on as an industry is understanding that our SecOps practices are built up around um different types of compromises, you know, cloud, uh, you know, coming in through email, but not so much recognizing anomalous behavior in the software development lifecycle. Um, and that you know, it comes back to like harden your agents, uh, least privilege, use a sandbox.
Paul McCartyMaybe don't use some MCP server they're just found on the internet, right?
Jenn GileUm, I mean, the key in this is actually the MCP server is not dangerous. It's that it's um taking untrusted data from sentry because sentry will look you look like you put a third party submission in the sentry. The MCP server here is uh a bit of a red herring. There's nothing malicious about it. It's just Untrusted input into the LLM.
Paul McCartyWell, that's exactly my point. You made my point for me. Let's apply the same thing to the MPC MCP server.
Jenn GileYeah, it should be saying no no no no no apps, right?
Paul McCartyLet's validate this input that you're about to pass on here, but it doesn't. It just passes it on, right? Which is like web app, you know, uh pen testing 101, right? Hardening 101. Um, uh, listen, I think from you know, when you were talking about earlier, I think the the main thing I was I was hearing from you um uh was that you know they go out of their way to to talk about EDR not catching this, and like you said, that's true, but it's also like why are you calling out that tool? That tool never like if you're an enterprise expecting your EDR to do that, well, then I'm sorry, you don't understand what your EDR tool does, right? It's like it's like somebody calling out, well, see you had all these soldiers on the ground with M16s. Why couldn't they shoot down the MiG-29? You're like, well, the MiG 29 is traveling at 500 miles an hour. That's not what that tool was designed for. Um, anyhow, sorry, rant over.
Jenn GileRant over. Okay. Before we move on, got a little happy to share. Uh we have uh Joshua here. Great information so far. Enjoying the learning and bookmark all of these. Awesome. Glad you're liking it. Always good to have a note. Anyone else who's listening, send us a note so we know we're not in this room by ourselves.
Paul McCartyDrink some coffee to Joshua here.
Jenn GileYeah, okay. Um, I don't know. Maybe the theme of this show is uh old manuals at cloud. I don't know if you know that uh reference, but uh I'm gonna Am I the old man in this reference? No, I I'm the old man. Um so you probably uh watched a show at some point called Mythbusters. We're gonna do some myth busting on uh malware myths. And the reason I wanted to do this today is I uh listened to a podcast earlier this week featuring um a leader from uh an application security company. And that's all I'm gonna say. Uh I don't want to call out the person specifically or the company or the podcast, um, because much of what they shared was useful. But there were some things that they said that were wrong. And I don't necessarily believe in calling out wrong things for the sake of it, but rather these are wrong things that are legitimately harmful if people believe them. And so I want to talk about them. Um so the first thing that this person said is malware only lives for between a couple hours, maybe up to three days. And that is just patently false. Um, I'm gonna check right now while you talk about why it's false because I want to look up and see if this package we've been talking about for a while is still live. So you tell the people, yeah.
Paul McCartyThere's another one, events runtime. They're actually from different threat actors, but they both have been up for like five weeks or something. Um, so explain why.
Jenn GileWhy is three days just a lie?
Paul McCartyYeah, I mean, listen, the are we getting I I at the heart of this myth is a truth, um, which is that from with these large account takeovers where the maintainer has been compromised, the industry, you know, us the security researchers are finding these things much quicker. You know, NPM's not, but anyhow, the besides the point. So that part is true, but then extrapolating that, Jen, to then say that all open source mailware, all software supply chain malware only lives for three days or less is just patently. I love how you said it because I literally said the same thing from stage the other day at the conference. It's just patently, materially not true. The reality is that the non um uh compromise ATO style takeovers, right? Which by the way, most of the app set companies aren't scanning with the same frequency, they're not looking for it in the same frequency that they are.
Jenn GileYeah, they're focused on good things going bad, not bad things being bad.
Paul McCartyAnd part of that, and I say this a lot, part of that is because the app set companies or the scanning companies, you know, again, we're not gonna say names for any of these, are buying into a myth, which is that you know, typosquatting and dependency confusion are not, you know, like people with mature app sec programs don't fall prey to these things, and that's just not true. I see it all the time. Because here's the difference. I'm just gonna say it, I'm brutal. The difference is that all you app set companies, you don't do incident response, right? You build a product, and your companies, when they get popped, they have to do their own incident response. I've been doing incident response for years, and I've been seeing the fact that typosquatting and dependency confusion have been affecting some of the largest, most mature from an app sec, you know, perspective, companies for years. So the reality is that those things and the ones that Jen is looking up, events channel, events runtime, they're just alive, was gonna be my point.
Jenn GileUh, we've been talking about some relatively sophisticated typosquat packages for maybe a month now. Uh, they've been reported to NPM. Um, they are incontrovertibly malicious, they are copies of existing legitimate packages. And this is something that threat actors do is kind of that more uh instead of the, you know, I'm gonna hit you as fast as I can and steal all your stuff, and you have no idea what's going on. This is the more tactical, like, I'm gonna slip this thing in, you're never gonna know you consumed it. You're gonna think you consumed a safe thing. And um the reason that they hang around a long time, there's they're twofold. One is what you talked about, Paul, is they're a little bit, I won't say harder to find, but it takes a little bit more effort to find them because you're not just looking at diffs and saying, oh, well, the old one looked like this and the new one has a nasty payload. Don't use that. So that's one reason. Um, but the other enough just doing that.
Paul McCartyThat's hard enough, right?
Jenn GileLet's be clear, that is hard. Um so it is hard to find these, but the other reason they have such a long shelf life is npm is not taking them down. Um, when they get reported and they're being reported, like in our case, by uh credible researchers, they're not getting taken down. And uh one thing that I thought was interesting in a disappointing kind of way is I looked at that easy day.js uh package yesterday or the day before when it got published. And what NPM had done at the time, I'm gonna look it up again because I'm curious, is they had removed the malicious version, but they didn't kill the package or the the entirety of it. They left, I'm looking right now, the original version 1.11.21 is still live. So they've done a weird thing here where that is a known threat actor controlled package that they have left live for who knows to slip something into again in the future. Anyway, this is a long rant to say malware only living three days is wrong. Don't get trapped by that. Yes, cool down periods are very effective and good, and you should do them and you should um, you know, use your package firewalls and your private registries to like catch these things that turn bad quickly, but just understand. Um, anyone who tells you, oh, you know, you don't have to worry if it's been longer than three days, like they don't know what they're talking about.
Paul McCartyYeah, I really wish I could cuss, but I'm not going to. That's bullpucky, right? Uh and with that, with that easy day.js, right? Clearly, the person at npm, right, doesn't understand the sequence of events because they've left that package up. That package was not a pre-existing package by that maintainer, which is your point, right? I'm just going a little bit deeper here, just to say the person at NPM saw that thinks, oh, that's owned by a legitimate person that was attacked, not realizing that that package, even though that one's not malicious, that's the decoy, that that package was built specifically by the threat actor, doesn't get that. And that's just the perfect example of why we still have this problem. Even when npm is moving on these things, they don't understand because most of the senior people there are gone, right? And they're they're relying on a bunch of people, you know, anyhow. I'm not here to you know, I'm not here to listen, I'm not attacking NPM stab. What I'm saying though is that npm and Microsoft and GitHub have not done what they need to do, which is increase their teams and build their teams and keep retention low. I mean, keep retention high. They're not doing those things. Yeah, sorry, rant two over.
Jenn GileWell, uh, second item. We've got four myths to bust here.
Paul McCartyThe second is one in real.
Jenn GileI know, I saw I was watching. Um they also said npm install scripts are going away. Um, not accurate. Uh npm install strict scripts are not going away. Uh, they are needed to make many packages function correctly. Um, what is happening is they're going to become opt-in by default rather than opt-out by default. Um, which is good, uh, but they're not going away. Okay. Uh the next thing that they said was package firewalls and cooldowns will eliminate 99% of risk. This is wrong for the same reason that malware only lives three days is wrong. I don't think I need to belabor that one. Um, but the one I do want to talk about a little bit more at length, and it ties into what you said, Paul, about um uh uh incident response as a mindset versus uh prevention as a mindset. This person said they don't care who the attackers are behind these software supply chain attacks, they don't care, they don't think we should care, they don't think it matters. And um that is true from a prevention stance. It doesn't matter who's behind it. If you can prevent it from coming in, you prevent it from coming in. But it does matter who's behind it if you didn't prevent it, because um, and I'm sure there's some like ridiculous, I don't know, criminal like law enforcement parallel that we could make here. Like you need to know if it's the mob or your neighbor's kid who stole from you, because there's really different um ways that you're gonna go about getting your bike back, right? I don't know why it's your bike. I don't think the mob's gonna steal your bike, Paul.
Paul McCartyUm, not gonna steal my bike.
Jenn GileUh but the point I do have a new bike. I know I really want to hear about your new bike, maybe not today. Um, the point I'm trying to make is you do actually need to know who the attacker is to the best that you can, uh, because that's gonna help you understand. Okay, what is what is their next step going to be? Um, if it's, you know, traditionally DPRK, North Korea, they're after um theft of cryptocurrency, financial gain. Okay, so they're probably not going to be, you know, doing ransomware. Uh team PCP, they're after your credentials, they want to get into whatever you have access to and get on to the next thing. So, like understanding who they are, like their you know, criminal psychology, I guess, uh helps you know how to respond to it.
Paul McCartyAnd they're tradecraft, right? Like to your point, if it's DPRK, you know, if it's um, yeah, if it's DPRK, they know you know that there's gonna be persistence via Invisible Ferret or Otter Cookie, right? You know what to look for, right? If you don't know who, if you don't spend the time figuring out who the bad guy is, you're not gonna know where to look for things like what is a persistence mechanism, where are they holding the files, what registry keys are in, like all those kind of things that you need when you're doing incident response. And again, I'm just gonna take another opportunity. That's an observation made by somebody that's never had to do incident response for a software supply chain attack. Full stop.
Jenn GileAll right, I think this is a good place for us to end today because we do have on our backlog we want to talk about DPRK trends in software supply chain malware. Yeah, but we've been going for a little over half an hour, and that one could take some time.
Paul McCartyAnd I still have to write the blog post, right? So we want to do the one-two combo.
Jenn GileSo uh next week, I think we'll plan on talking about what's going on with Lazarus Group, how they're evolving their malware. Uh, what I will leave people with is again, this comes back to it kind of does matter who the attackers are. We see uh we've been seeing trend wise um Lazarus group doing innovations in the space of malware, and then that getting picked up by other threat actors. As far as we know, they're the first threat actor to really abuse VS Code tasks.json files, for example. Um, so yeah, it matters.
Paul McCartyEverybody's doing it, right? Yeah, now everybody's gonna do it. Everybody's using VS Code 100. Yeah. Right. I think this is gonna be that's gonna be a really good one. Let's hope there's no big attacks next week that will then, you know, knock the DPRK innovation conversation to the next week. But let's cross our fingers.
Jenn GileYeah, for many reasons. We hope there's no big attacks uh between now and the next week.
Paul McCartyUh yeah, there might be something to talk about in terms of team PCP next week, too, as well. So we'll we'll tease that as well.
Jenn GileSo okay, right on. I look forward to it. In the meanwhile, uh now that we're done with our rants, let's go take a breath and get on with our days. Have a good one.
Paul McCartyThanks everybody for listening. I appreciate it. Sorry, don't tell you. Bye.
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Open Source Security
Josh Bressers
Future of Threat Intelligence
Team CymruAbsolute AppSec
Ken Johnson and Seth Law
Coffee, Chaos and ProdSec
Cameron Walters and Kurt Hendle