The OpenSourceMalware Show
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.
Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.
OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more.
https://opensourcemalware.com/
The OpenSourceMalware Show
New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This week we talked about:
- New npm worm hits Keyv and cacheable. Jared Wray's GitHub account was compromised on Tuesday, and threat actors used it to publish a worm based on the open-sourced Mini Shai-Hulud malware. The worm spread to over 400 packages, with ServiceTitan alone losing 100 packages, and it searches developer machines and CI runners for credentials across GitHub, npm, AWS, Kubernetes, Vault, Azure, Google Cloud, Terraform, Docker, and Slack before exfiltrating them. We also talk about how this got caught within minutes despite GitHub's recent claims of proactive pre-publication malware scanning.
- The WEL1DROPPER campaign is flooding npm with AI slopsquatted packages. Over the past 72 hours, more than a thousand malicious packages have been published to npm as part of a campaign we're calling WEL1DROPPER. It doesn't rely on install scripts at all, executing instead when a package is imported, and we believe it's loosely connected to the earlier Moika campaign based on shared tradecraft. We dig into why attribution to Russian threat actors is complicated given the campaign also targets Russian and Belarusian financial institutions.
- DPRK is using a new C2 technique we're calling NullReceiver. We found DPRK-linked malware hiding its C2 IP address inside the recipient address of a completely empty Ethereum transaction, an evolution of the EtherHiding technique that fixes its biggest weakness: a fixed, publicly known destination address. We've confirmed at least 10 packages using this new technique so far.
Episode Resources:
Hey, it is Friday, August 7th. Recording on a different day this week because Paul and I are in Las Vegas. We're live from the West End right before we head over to LVCC for DEF CON. So we wanted to sneak in a podcast and an episode so we could talk about three things that have happened in the last week. But before we get there, Paul, what are your kind of like uh impressions so far? We've been here since Sunday. We did Las Vegas. Uh besides Las Vegas, we did Black Hat, obviously starting on DEF CON. Lots of events, lots of people to see. What's your takeaway so far?
SPEAKER_01Apps like buyers are very different when SecOps buyers. I think that my takeaway is that the industry is waking up to the reality of itself for supply chain types, um, are we doing present and a danger? But I think a lot of people still don't really understand how it works. Um and I guess that's why we're here, right? That's why we're doing what we're doing.
SPEAKER_00Yeah, fair enough. Um so unfortunately, predictably on Tuesday, yeah, Tuesday, uh we all collectively woke up to a new NPM worm. Uh we kind of figured after the success that Team PCP had during, I don't know, hacker spring break, whatever you want to call the set of things in San Francisco back in March, um, that we figured an attacker would try to pull the same thing this week. So uh pros and cons. Uh on the positive side, this thing didn't go as crazy. Um there's some scuttle butt that the attackers didn't quite uh do things in the the most complete and high quality way. Uh, but on the negative side, uh over 400 packages were affected by this worm. Um we've been in communication with the person who, as far as we can tell, was the the patient zero, um Jared Ray, who maintains, I don't know if it's KV or Cave, I don't know how you pronounce it, and uh cashable, but he maintains a couple of projects. Um his account was taken over on Tuesday. He was locked out for at least, it seems like maybe 12 hours while threat actors published the worm and then uh it made it into you know other parts of the ecosystem. Um what uh what do you think is notable here?
SPEAKER_01Well, I think the first thing that's notable is that while you're right, that the threat actor in this case, we don't believe that this is a highly competent threat actor to treat down the words carefully. Um but that said, my my point I'm driving at here is that even though this is not a highly competent threat actor, at the same time, this was still a very unfortunate very successful attack in the sense that it infected a lot of packages, had a lot of reach. Um Jared's packages alone are downloaded. Um so it just goes to show you that you know, even if somebody fumbles the hand grenade, it's still pretty freaking dangerous.
SPEAKER_00Yeah, uh there's one particular ecosystem that just got uh decimated by this a company, uh service called Service Titan had a hundred packages compromised. Uh I don't know if that's all of their packages, but that's certainly a lot of packages. And that seems to be the biggest um single impact that we're seeing with this attack.
SPEAKER_01Yeah, we also heard some inside baseball that this might be related to a long wind legacy cat. We haven't found that yet, but if that's the case, just goes and showed you.
SPEAKER_00I'm sorry, how dangerous this is poor Paul uh has been hit with a cold this week. It's not the uh you know security plague that might catch us uh off guard, but kind of while he's recovering, just in brief, you know, what the malware did is it contains uh an obfuscated JavaScript payload and it has either a math underscore init.js or math underscore symbol.js file. They both have the same payload, it's uh roughly the same file hashes. And what it does is it searches your dev machines, your CI runners for credentials. Surprise. Um it's looking for GitHub, npm, AWS, Kubernetes Vault, Azure, Google Cloud, Terraform, uh Docker Slack, like pretty uh diverse kind of like infrastructure-related credentials. Um, it exfiltrates what it finds. Um what we uh know so far is it's based off the open sourced mini Chi Halud worm that came out in April, May timeframe. Um and it uh let's see here, it does use the GitHub dead drop in the same way that we saw Chai Halud do last year. Hey man, do me a favor and mute. We got we got an echo chamber. Sorry, everyone, we're sitting across the table from each other. It it gets a little funky sometimes. But yeah, they've got um GitHub dead drop. Uh they have a primary way of X filling as well. Um I do believe, correct me if I'm wrong, that this is one that ran on a pre-install or post-install script, right?
SPEAKER_01Yeah, I think that's correct.
SPEAKER_00Um, I don't know how deep we need to get into it, but the thing that I think is worth um having a little bit more of a conversation about is just last week we were talking about GitHub's new announcement where they said that they would be proactively scanning packages um pre-publication, looking for malware. And uh this was found by several security researchers within minutes of it being published. This was not complicated, sneaky malware. And so that means, I guess, one of two things either the pre-publication scanning is not turned on, or it's not tuned to find this kind of malware. So um just kind of a reminder that just because they say it's turned on doesn't mean it's going to be uh immediately preventing these kind of exploits.
SPEAKER_01Uh I'm sure you agree. Yes, I do. I think that's a great segue to one of the other two things we want to talk about today.
SPEAKER_00Keeping the massive thing, yeah.
SPEAKER_01The pre-publishing, you know, scanning that supposedly is being turned on. And I and my understanding in general is that it's being rolled out gradually, but that's also kind of ignoring the fact that we know that this has been in place for months or or like a year or more. So they've been using the Microsoft scanning inside of um NPM um for a while now, and so to say this immediately. So, and yet it's not catching all these big things that we're about to talk about.
SPEAKER_00Yeah, so big thing number two, which I would say uh is a bit under the radar because it's not a worm, it's not an account compromise, is uh yesterday morning, you discovered a massive new campaign that is publishing just hundreds of packages to NPM. In the last now 72 hours, we've discovered over a thousand uh malicious packages pushed to NPM. I'll drop the link to the analysis that we put up yesterday morning. Um you're calling this the well dropper campaign or well dropper malware. Um there's a couple of things that are notable about it. Uh one is, again, clearly not getting blocked by anything that's coming through on NPM. Um two, as far as we can tell, uh attribution looks like uh Russian threat actors. We talked about a campaign called Moika a couple months ago. There's reason to believe it may be the same threat actor. We don't see as much uh Russian uh malicious open source as we do things out of North Korea, obviously. And then the third thing that I think is, well, I guess there's a third and a fourth. Uh the third thing I was going to bring up is this does not uh take advantage of install scripts, post install, anything like that. Um so if you know you're kind of thinking, oh, well, if I just turn off npm like lifecycle scripts, I'll be safe. This campaign doesn't take advantage of that. And then the final thing I'll say is uh many of these look to be uh a very specific type of typos squat, which is an AI slop squat, slop squat, say that five times as fast. Um so yeah, the thing that uh to like kind of dig in there is more and more we're seeing malware that's targeting agents, not humans. And um these are uh much like other typos squats, they're forks of benign projects that have been uh poisoned in some way. Though interestingly, in at least one case that you looked at, Paul, uh you found that it didn't actually do the thing that it claimed to do. So it was both a slop squat and a, I don't know, not a very good package. What do you want to say about this well dropper campaign?
SPEAKER_01Helps if I go off mute. Um yeah, I mean, I think the the the well dropper thing is uh, you know, I think people are probably lumping it into a kind of scam junk um category like Indonesian foods. But in this case, the payload is actually very dangerous. Um so there's a couple things I want to talk about here. You know, we've loosely attributed this to Russian threat actors because they're using their backup stage two is being pulled. Um, well, there's a backup function that will pull the stage two from text records uh from a dot RU domain. Now I thought that.ru domains you couldn't buy those in the West, but they're you still can buy them until September 1st, 2026. So and some people have said, some other researchers on Twitter have have said that you know they're trying to make it look like it's Russian. And I agree, it kind of feels like that. But uh at the same time, this has um some some singles and some um similarities to another campaign that you saw Moika. Um that I personally genuinely believe that Moika is a real Russian campaign for a number of reasons, some of which I can go into and some of which I can't. But I guess the point is just because somebody uses.ru domains right now at least, doesn't mean that the you know it's it's officially attributed to uh Russian threat actors. There were no surreal characters in any of these packages. And this is the weird thing is that they're targeting mostly Russian and Belarussian financial organizations. So like if you're a Russian threat actor, why would you do that? Because you know that's a death sentence in Russia. But here's the other thing is it also has like one of them I was looking at had the CIS checks, right? So it's looking, am I running in Russia? So why would you be targeting Russian you know financial institutions if you also have the CIS block there? So it's it's a confusing thing. But in the meantime, this thing is pummeling NPM. At one point, I saw one package per 51 seconds. So and each one of those, almost every single one has its own email address. So just the mass, you know, the automation that these thread actors are using to create this stuff. And npm does not have any response. Most of these are being tagged by LSV and us and you know, and being labeled that way. So I don't know where this pre-published standing is, guys. Come at me.
SPEAKER_00Okay. Uh next topic is something that we actually published Saturday, I think. Uh, right as we were, I think you were mid-flights uh on your way out to the US. I was, you know, packing my bags. Um you made a discovery about some new uh technique that uh North Korea's Lazarus Group is using, or at least it looks like it's Lazarus group, but it certainly is North Korea. Um you've named this technique null receiver. It's a new uh way for hiding a C2 IP address inside the recipient of a completely empty Ethereum transfer. And um, you know, if you're more used to the application security side of this, of like yes, no, is this package bad? You may not know a lot about C2, but essentially once the malware fires, the threat actors have to have a way to get your stuff out of your environment, whether it's you know via a rat or something else. They have to have a way to come in and talk to your machine. And um, they have been using Ethereum, they've been using blockchain technology to do this for at least, is it two years now that it's been observed? Maybe a little, I don't know.
SPEAKER_01Uh you're on Neat Man trying to do the do the needful. Um, I think ether hiding has been around for a year, but you're right. Some of the earlier Ethereum stuff goes back, I think, to late 2023.
SPEAKER_00Yeah, I feel like it's somewhere in there. So um, you know, kind of what is ether hiding? Why would North Korea be doing this innervation innovation? So ether hiding is a technique that um works by sending a transaction to Ethereum's like burn address, and they embed the secrets such as like a C2 URL or even a malicious script inside that transaction's data field. And the destination itself is meaningless. Uh, the data field's what matter. And this um has been really highly successful at evading detection uh from you know your EDR, uh, whatever um threat detections you have set up because it looks legit and it um, you know, the where it says it's going is not necessarily where it's going. It's the the memo field, I believe. Uh but ether hiding has some weaknesses. Um it reuses the same fixed public burn address across every campaign, and that makes it much easier for us, thank you, uh, to watch it. That's how GTI caught it. Um, you know, that if you monitor that burn address and then flag anything unusual sent there, that's kind of the um uh, you know, hack, so to speak, to be able to manage it uh in your detections. Also, um, it's slightly more expensive. Uh so Paul, talk about what you discovered with null receiver and why it's able to get around um kind of the the drawbacks of ether hiding. And I'll say we've so far we've discovered 10 packages that are using this new technique. Um, we're linking it kind of softly to the contagious interview campaign. There's enough overlap there that it looks like it's part of that particular um. So yeah, lay it on us. What's interesting here?
SPEAKER_01Yeah. So in in typical ether hiding, um, what makes it unwieldy over time is that you use a new set, you use the same uh blockchain address. And so they this this set of blockchain addresses, we've been watching these things now for like a year and a half or two years, and they can be used across. And this is one of the ways that you know, one of the easy ways that you're able to attribute this to North Korea is that you know they used it in in the some of the early Mintin stuff, and they used it in you know Task Shock, and right now they're using it in other places too as well. But the problem there is that, like you said, they're using specific blockchains, they're using Tron and Aptos in the Binance BSC thing. Um I still don't understand that one, but anyhow, um and those three blockchains have these memo fuels. So the what you enter into the blockchain address itself you know is immutable. You can't choose it, right? That's how the blockchain works. But these memo fuels allow you to change it. Now the problem though is that it singularly kind of pivots on that known uh ether uh uh that Tron address or the apps, and everybody and their brother is looking for those. Uh everybody and their brother and their sister, we want to be gender non-specific here, are looking for those uh addresses. So uh DBRKA probably was sitting there in their Friday hackathons and thinking, how can we do this in a more lean way where we can change the blockchain address? They came up with this really unique technique, which is basically what they do is they take a specific Ethereum uh address and they can change it. You know, they can change it up if they want to. And basically what they then do is they send a transaction of zero uh zero anything to it. So they they spend a little tiny bit of gas. I think that's how this works. I'm not a crypto guy, not pretending to be one. Um uh, but they don't have to actually send any any money to it. Uh and the the destination that is that they're sending that to doesn't exist, right? It does it's not you can't send stuff to that destination. Uh but instead in that address they're hiding um they only can there's not a lot of characters there. So they could hide an IP address or a short URL, or maybe a very short like curl to a to a redirection string when it was like short dot gy's or something like that. They can't put a lot of stuff there. But what makes this really great then is they put that in stage two in front of Ether idle. So we've already seen this. We've already seen this where, and a couple of people asked me on Twitter how do how am I attributing this to DPRK? Well, basically just take the standard six-stage DPRK kill chain with US, you know, invisible ferret and all the other stuff, and they're just slotting in now at stage two, null receiver, and they still have in some cases, they still are using ether editing at stage three and four, right? So it's um you know, there's you know, and and those and ether hiding is still calling the original trial one, so they're just hiding it at the beginning of the kill chain. So anyhow, that's me going into depth about how we can we know it's TPRK and we can connect it to a lot of activity because in those cases where they are using ether hiding, we can just point at all those other things, hundreds, hundreds and hundreds of packages that use it. So um, yeah, I'll pause there. The cloud drop worked.
SPEAKER_00Good, excellent. Um, that's kind of the majority of what we had to talk about today. I don't know that we'll go the full, even like half hour that we've been doing, but um, I want to talk about something you and I got to do yesterday that I thought was kind of special. Uh, our friend Mackenzie over at Aikido uh fired up an email you know a couple weeks ago and said, Hey, a whole bunch of us that work in the malw security research space are going to be in Vegas. Let's all film a podcast together. And so we got together uh yesterday afternoon with Mac as well as uh John from Aikido, who uh was the CEO of Root, which was acquired recently. Uh also in the room, we had Step Security, we had Ox Security and Socket. So uh, you know, we're a little bit um separate from those types of vendors, but certainly they're all direct competitors. And so I thought that was pretty special. We got to get together and have like a real conversation about what's uh problematic in the industry right now, what the challenges are, uh, in what ways vendors are making things better and honestly worse in some ways, and um what maybe we can be doing collectively. So I just thought it was such a great example of like community and the value of getting out of our basements. My basement, your shed. Uh and cottage. Cottage. Okay, I'm sorry. Well, excuse me. Um and you know, just getting out and like seeing the people because uh this is you know, it's a big world, but also it's really small. And, you know, I don't think any of us would be successful if we didn't have the the connections and relationships. So anyway, uh that all is a teaser for uh Max podcast episode as a secure disclosure that's gonna have uh a record setting, I think six guests on it. Um should be pretty fun.
SPEAKER_01Yeah, and I just wanted to, I don't have anything really to add. I just want to say thanks again to Mackenzie and to Akido for putting it together and to Socket and Step and Ops for being a part of it. I think this is the kind of thing that we need to do more. And I think all of us in the room yesterday agreed that we need to do more of this, right? We need to have this kind of relationship where we're not just trying to compete against each other. Are we competing? Of course we are, right? But at the same time, we're us not so much, but at the same time, you know, it's important for us all to be part of this community. Um so big, big shout out to them.
SPEAKER_00Yeah, and like uh the necessity for a collaborative relationship is never more clear than when you and I have these conversations about, hey, we just found a thousand new malicious packages that are hanging out in NPM. You know, what can we what can we collectively do to try to get them taken down? Um, you know, we were talking about the situation with the NPM worm, and uh ourselves included, multiple vendors, you know, reached out and tried to help this guy because you know, the person who was compromised is not a security person. He doesn't have the support of a big company. You know, a lot of times they're a little bit like, uh, what do I do? Oh no. Uh this thing that I've you know built and taken responsibility for has gotten taken away. And uh, you know, unfortunately, in um you know, the case of the person who was compromised, they weren't getting help from more official channels.
SPEAKER_01Yeah, it was really unfortunate. And we've we've been seeing this, so we've talked about it on the podcast before, but I really think it's incumbent on GitHub and VPN to come up with a better response plan than locking out. And I get, you know, especially when the GitHub repositories sitting behind the NPM packages are also potentially malicious. I get that locking them out to some extent makes sense. But at the same time, what we then create is we create the situation where the maintainer themselves can't be a part of the fix, right? Um, and so then there's a lot of latency while these offshore emails go backwards and forwards with the maintainer. So I really um I'm reaching out to GitHub. We talked to a few people from GitHub last night and saying this is a problem, and we need to have a better instant response plan here from the GitHub side, straight up.
SPEAKER_00For sure. Well, uh again, we're taking off for DEF CON here. We've got a workshop today, a panel later today, talk tomorrow, and then we're out of here because uh eight days in the desert is uh possibly eight days too many. It's a lot, but we've had a great week.
SPEAKER_01Yeah, I love this week. Uh I'm desiccated, but as I'm sure everybody else is. But um, I you know, just uh want to say thanks everybody for listening. And we've had a lot of people come up to us this week and say they really like the podcast, they really like the content that we put out there. We do this because we really love doing it. Jen and I are doing this well now because we really love doing this, and um it means a lot when people you know do that. So uh just want to you know say to those people that did you know came up and met us, thanks so much. That really makes us feel good. Thank you.
SPEAKER_00Yeah, plus one of that uh keeps us going, makes us feel like we're not just talking to each other here in a hotel lobby. Um, you know, that we're doing some good. So with that said, uh, if you're in Vegas, hope you're having a great time. If you're not, it's okay. Uh you know, you may have some FOMO, but there's lots going on. So we'll see you next time.
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Open Source Security
Josh Bressers
Future of Threat Intelligence
Team CymruAbsolute AppSec
Ken Johnson and Seth Law
Coffee, Chaos and ProdSec
Cameron Walters and Kurt Hendle