The OpenSourceMalware Show

New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation

OpenSourceMalware Season 1 Episode 16

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 24:32

This week we talked about:

  • New npm worm hits Keyv and cacheable. Jared Wray's GitHub account was compromised on Tuesday, and threat actors used it to publish a worm based on the open-sourced Mini Shai-Hulud malware. The worm spread to over 400 packages, with ServiceTitan alone losing 100 packages, and it searches developer machines and CI runners for credentials across GitHub, npm, AWS, Kubernetes, Vault, Azure, Google Cloud, Terraform, Docker, and Slack before exfiltrating them. We also talk about how this got caught within minutes despite GitHub's recent claims of proactive pre-publication malware scanning.
  • The WEL1DROPPER campaign is flooding npm with AI slopsquatted packages. Over the past 72 hours, more than a thousand malicious packages have been published to npm as part of a campaign we're calling WEL1DROPPER. It doesn't rely on install scripts at all, executing instead when a package is imported, and we believe it's loosely connected to the earlier Moika campaign based on shared tradecraft. We dig into why attribution to Russian threat actors is complicated given the campaign also targets Russian and Belarusian financial institutions.
  • DPRK is using a new C2 technique we're calling NullReceiver. We found DPRK-linked malware hiding its C2 IP address inside the recipient address of a completely empty Ethereum transaction, an evolution of the EtherHiding technique that fixes its biggest weakness: a fixed, publicly known destination address. We've confirmed at least 10 packages using this new technique so far.

Episode Resources:

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

Open Source Security Artwork

Open Source Security

Josh Bressers
Absolute AppSec Artwork

Absolute AppSec

Ken Johnson and Seth Law
Coffee, Chaos and ProdSec Artwork

Coffee, Chaos and ProdSec

Cameron Walters and Kurt Hendle
The Secure Disclosure Artwork

The Secure Disclosure

Mackenzie Jackson