The OpenSourceMalware Show

Open VSX security improvements, new PolinRider researcher, shady vendor practices

OpenSourceMalware Season 1 Episode 12

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 46:41

This week we talked about:

  • PolinRider jumps the fence — Paul's research on North Korea's automated repo-hijacking campaign spreading into the Go and PHP ecosystems without any extra effort from the threat actors
  • Cybersecurity startup publishes infostealers to npm — a vendor publishing malicious packages to manufacture threat data for its own marketing, and getting their npm account pulled for it
  • MeetingTV sues Palo Alto Networks — a lawsuit alleging Koi Security's AI-assisted analysis hallucinated a company's domain onto a C2 infrastructure list, with real business fallout

This episode also features an interview with Mikael Barbero (Head of Security, Eclipse Foundation) on OpenVSX security — We covered OpenVSX's explosive growth, its pre-publish scanning pipeline, looking for "sleeper malicious" extensions, publisher verification, and token management.

Episode Resources

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

Open Source Security Artwork

Open Source Security

Josh Bressers
Absolute AppSec Artwork

Absolute AppSec

Ken Johnson and Seth Law
Coffee, Chaos and ProdSec Artwork

Coffee, Chaos and ProdSec

Cameron Walters and Kurt Hendle
The Secure Disclosure Artwork

The Secure Disclosure

Mackenzie Jackson