The OpenSourceMalware Show
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.
Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.
OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more.
https://opensourcemalware.com/
The OpenSourceMalware Show
Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This week we talked about:
Rust arrayref compromise tied to DPRK infrastructure: A compromised maintainer account published malicious versions of the arrayref crate, along with internment and append-only-vec, adding a typosquatted build dependency that downloaded and executed a remote binary at compile time. arrayref alone has more than 245 million lifetime downloads and sits in roughly three quarters of all Rust environments. Wiz Research has tied the campaign's infrastructure, including a shared C2 endpoint pattern and overlapping IP ranges, to the same DPRK actor behind the Mastra and Axios npm compromises.
StubMaker spreads from RubyGems to npm: What started as a RubyGems typosquatting campaign targeting bundler, i18n, rake, and activesupport turned out to share byte-for-byte identical payloads with a separate 40 package npm typosquatting cluster targeting axios, chalk, commander, lodash, react, and typescript. Both campaigns deliver the same 22MB Rust loader and embedded Go infostealer, confirmed by matching SHA-256 hashes, giving one threat actor two independent paths into any organization running both a Ruby and a Node stack. There's also evidence that this campaign hit the PowerShell ecosystem.
DIY binary payloads make a comeback: Paul has seen a sharp increase over the last two weeks in software supply chain attacks bundling compiled binaries (C++, Rust, Go) instead of sticking to the interpreted languages that dominate malicious open source. The theory: less experienced threat actors are following old malware-writing conventions, possibly with an assist from AI coding agents, without realizing that shipping a binary inside an npm or RubyGems package is itself one of the biggest red flags an analyst can ask for.
PolinRider reinfection wave using NullReceiver: We're still continuously seeing developers talking about getting reinfected with PolinRider. This latest iteration swaps out EtherHiding for NullReceiver as its stage two hiding method, and Paul and Jenn walk through why victims keep getting reinfected even after they think they've cleaned up: the malware lives on the developer's machine, not just in the repo, and it can commit to Git history without leaving an obvious trail.
Episode Resources:
Hello, hello. It is Thursday, August 20th. We have a kind of last-minute list of things to talk about. Hot breaking news. There was a compromise in the Rust ecosystem that we're going to get into. We're going to talk about some research that we did earlier this week on a dual ecosystem compromise in NPM and Ruby. And uh a little bit uh around binary payloads. Paul, where do you want to start?
SPEAKER_00Oh, just pick one. We're yo we're YOLOing it today. YOLOing it.
Jenn GileWhy don't we start with the Rust one since I know you were looking at that right before we got online? So to kind of just uh summarize in brief, um, it was discovered today that a maintainer, uh D Roundy, Drundy, I don't know how you pronounce it. DR. Yeah, uh, was compromised by threat actors in an account takeover. Um, they did something that we've kind of generally seen in the account takeover playbook this year, where they didn't actually push malware in the existing uh legitimate packages, but what they did instead was they published um six net new packages that were all malicious and then uh linked those to the existing packages as malicious dependencies. So again, if you're scanning the top level package, everything looks fine. But if you're not looking at the dependencies, uh, then you wouldn't necessarily know that you were pulling in malware. Um, so we've published on our LinkedIn and we'll um share some more details the uh IOCs to look for. There's a nice little script from uh Rust that can help you find out if you're using any of these packages. Um Paul, what do you what do you want to share? What do you know so far?
Paul McCartyYeah, well, so the interesting thing is this actually dropped last night before I was going to bed. And so I stayed up late um working on it. So they've been in, they've been in open source malware. Well, most of them have been in open source malware because, like all attacks, you know, when the initial word came out, we only thought this was like two packages. Um and then of course, over um we realized there's more, yada, yada. But um, yeah, you're right. This follows kind of the the npm kind of playbook, and we'll get to that in a second because I've got something I haven't because we're YOLOing today.
Jenn GileI didn't even send Jen this link from Wiz, but um no, I actually did see the whiz when I just didn't have time to write in. Yeah, I was doing a little research before the show, so I I think I know what you're gonna talk about.
Paul McCartyYeah, cool. Sick. Um, yeah. So basically, this attack compromised uh one maintainer and it compromised three of their existing legitimate packages, one of which is a Ray Ref, which is a very popular Rust package. It's been downloaded 250 million times. Um downloaded several million times a week. It is so popular that it that by some accounts, I saw somebody say that it was in 76% of Rust projects. I have not verified that, but let's just let's just it's safe to assume this is a very, very popular package, right? So there's a there's probably a better than even chance that the uh or worse than even chance if we think about it that way, that you've got this in your Rust project. Um and yes, it was up for 90 90 minutes, it was online for 90 minutes. Um, but some of the ancillary packages were up longer. Um, and so you know, total time. Anyhow. All right, so when I was looking at this last night, I I thought to myself, you know, I was sleepy, and I was like, this kind of feels like other things that I've seen, but then I went to bed. And in the meantime, um, Rami and the Wiz team has have come out with a blog post basically tying this attack, this Rust Array ref attack, to um the same DPRK North Korean threat actor that's behind Mastra and some of the other. Yeah. Now, and they're they're basing this on a couple of things. First, you know, the look and the feel of TTPs. Like I said, I my spidey sense last night was going off like this.
Jenn GileYeah, why don't you talk a little bit about it? Because the um intel I have is pretty thin. What does the malware do? What's what's unique about it, other than this pattern that we're seeing of a direct dependency calling it transitive? What can you tell us about the malware?
Paul McCartyAnd and I think that's the first thing. It's a it's unique where they add that that's that follows the kind of the um the master playbook. Um what other what's the other group? Let me just really quickly here look at what's the other group of those NPM packages that all followed. I'm trying to remember, they all blend together now, right? So it's like um all right. Well, anyhow. Uh so yeah, what does the malware do? Um, it is not focusing on CI. Continuous integration does not, it's this is focusing on smash and grab on an endpoint. Um, and so um it's been kind of modified to do that better. So stripped out a lot of the things that were there for worm versions of the malware you would typically see like this in in worms, a lot of that's been stripped out in this case. So it's an info stealer, it's a crypto stealer, it's fast, it's efficient, it's not great, but you know, I mean, uh I've already seen people say that they were compromised by it, right? So the reality is that unfortunately it was um it was effective. And when you can you getting back to your question about what does it do? When you zoom out a little bit, it looks really, really similar to these like B grade DPRK, B and C grade DPRK campaigns that we see all the time. Um B grade.
Jenn GileUm so is this similar malware to what you see in DPRK typosquats, or is it different from what you tend to see there?
Paul McCartyYes, it is it is very similar. Uh and so, you know, because there's this whole pantheon, this whole like kind of grouping of DPRK, all the way from the low-end stuff, which is really simplistic and stuff that's built to be brought in from other packages. And then there's the big complex packages that have like the six, seven stages in the kill chain. This feels like it's somewhere in the middle. Um, and so uh that's part that's partly what Rami talks about in this article. Um, I loosely agree with with the things that they've said. You know, I haven't read it, I mean I've I've read it a couple times, but uh I think the most important thing is they have tied it to some specific shared IOCs. And I think the look and the feel of the TTPs, that spidey sense that I got, this is what you get as a researcher when you you smell something. You're like, oh, there's some blood in the air right here.
Jenn GileAnd you're well, it's like I think we'll actually talk about this later, what we saw with the Rust and NPM camp or uh Ruby and NPM campaign earlier this week.
SPEAKER_00Right.
Jenn GileI'm just kind of flipping through uh the Wiz blog, and I see it's got shared C2 endpoint pattern, not exactly the same endpoint uh as with the Master campaign. So that's interesting. Um, like you said, sometimes these patterns uh may not 100% match, but it's close enough and unique enough that we can kind of like, you know, let our eyes go fuzzy and be like, oh yeah, those things look the same.
Paul McCartyYeah. And one of the things that we're seeing a lot, and we saw this with with Team PCP and other non-DPRK threat actors, is we're starting there's starting to be a move away from IPs at the at the earlier stages of the kill chain to like the use of these throwaway domains. And I think part of that is because dprk and other threat actors have found ways to buy domains from registrars using crypto. And that's why I was I was bird dogging in GoDaddy earlier, uh sorry, last week, trying to figure out is is there a way now to buy, and it looks like there is a way now to buy domains in GoDaddy's registrar via crypto through these other payment processes. So we're seeing an increase in this, which is good because they're great little indicators to have, right? Um, but uh it's just you know, when you're watching the kind of tradecraft, this does feel like DP DPRK-ish. Is that uh is that an authoritative attribution statement? No, it's not.
Jenn GileYeah, well, it does say in the Wiz blog that um a victim has reported C2 traffic to an IP that's also from the Axios attack back in what March or April? So that yeah, we're seeing multiple indicators of shared threat actors. And maybe this is a good place to pause when the Axios attack happened, when the Mastra attack happened, these were unknown threat actors at the time. Uh, they did happen around the same cluster as major account takeovers by Team PCP. They were not claimed by Team PCP, uh, but we've seen um people attributing those attacks to North Korean threat actors with a degree that um of credibility that we trust, in addition to chalk and debug. So we've got a pattern here where North Korea is effectively taking two different um strategies. Like if we were talking about this as a company and their go-to-market strategy, you know, their first go-to-market strategy was that typos squatting contagious interview, now Paul and Writer, very targeted on getting into an individual developer's account, getting persistence on an individual developer's machine, quietly spreading, trying to stay on the radar. The other uh part of their go-to-market strategy are these higher profile smash and grab account takeovers where they know that they're not going to uh maintain control for very long, and they're not going to uh they're there. This is not a typos squat that hangs out for months, or you know, people don't know necessarily that they consume something bad for months. So interesting to see them using both tactics, not necessarily surprising. Um, both tactics have merit. The things that we do to protect ourselves against an account takeover broadly have no uh protective uh elements for this other, you know, typosquatted type package attack. Whereas, you know, if you're focused on, I don't know, um, making sure you're only consuming packages from legitimate sources, then you know, you're more likely to have that implicit trust in a package like the array ref that got compromised today.
Paul McCartyYeah, I mean, I totally agree. I mean, I think we've we've said it before, and the reality is that the DPRK, you know, spreads themselves, you know, they're like they're like Paul Molliff, they've got products in all the areas. It's like when you call when you call Samsung, press one for a microwave product, press two for an automotive product. I mean, DPRK has got you covered. If you want sneaky and long lived, they got that.
Jenn GileIf you want to never mind the IT workers and everything else that they've got, right?
Paul McCartyRight, they are very adaptive and they are spreading themselves across the whole. And I love your use of go to market because I coined the term last week, go to target. This is they they found their you know, they're constant. That's why they use all these campaign marketers. Sorry, campaign markers. They're trying to figure out what are the most successful ways that they can compromise people.
Jenn GileYeah, you gotta have your uh metrics so you know what's successful, right?
Paul McCartyDPR Pyong Peng has got his kit KPIs, baby.
Jenn GileOkay, shall we move on to Stub Maker?
SPEAKER_00Let's do it.
Jenn GileOkay. Uh to summarize, over the weekend, uh we did some research specific to Ruby Gems. Uh, we found a cluster of packages. It started with two packages initially. That's what you sent me when we started our write-up. And then as I started poking at it, I was like, oh wait, uh, they've managed to resuscitate, revive one of these packages, and spread even further. So, long story short, um a whole bunch of Ruby typosquats were published over the weekend. Uh, they managed to do it across multiple accounts. And uh uh maybe a trick that's unique to the Ruby ecosystem is when Ruby killed those first two packages, they seemed to figure out pretty quickly that they were malicious, you know, even at the same time as we were analyzing them. Uh so they killed those two initial packages, but uh they don't seem to have a security mechanism in place to make sure a known malicious package doesn't get reactivated. And so the threat actor was able to create a new account, come back into Ruby and resuscitate one of these packages that had been taken down and publish a new malicious version to that package that always should have stayed dead. So I thought that was some really interesting Ruby specific behavior. The other thing as I was looking at this campaign and looking at every package page side by side is they were all um they had the owner account and then they had the author account listed. And the owner account that's tied to an actual account with a login and everything.
Paul McCartyThe author's account.
Jenn GileYes, a Ruby Gems account. The author is what I would describe as like a vanity label. It can be anything that you want. Uh, there is no mechanism to force you to make the author, you know, the same as somebody who is in the ownership group, anything like that. And so we had, you know, things like an owner with sort of a random string of letters and numbers. And then the author name would be something like Blake Miller or Taylor Gray or Avery Collins or Quinn Parker. And at least to me, being American, I saw those names in a in a list and I was like, gosh, it's like they they had like a random name generator targeting children of, I don't know, young Gen Xers or millennials.
Paul McCartyYou know what I when I saw those names, I thought somebody's created a random name generator based on the country music awards.
Jenn GileIt could be.
Paul McCartyIt seems so.
Jenn GileI mean, there were some like very clear indicators that these were sketchy before you even pulled the payloads, but we proactively scan Ruby. So as things come into Ruby, we're looking at it. That's how your uh detection got set off. So why don't you talk a bit about the malware and then we'll segue into the NPM part of the campaign?
Paul McCartyOh my gosh. But now you're putting me on a spot. Like I've I've I've forgotten.
Jenn GileI know our brains have like wiped, and that was the four days ago. Why would we think about that?
Paul McCartyIt was. Let me real quick, uh, let me just cheat here in the background and just uh bring up the blog post so I can remind myself. Um I uh there we go. I'm I'm here. Um yeah, so I mean, I think the the all the things that Jen said uh are true. Um this uh campaign. Um I'm trying to remember exactly how the oh yeah, so basically they were targeting um I-18 and um uh bundler, uh other reputable, like well-adopted, like active support was in there. The vast majority of them were like simplistic I-18 um kind of uh you know, uh just uh brute force kind of typosquats, right? Not particularly well thought out. But the and Jen and I talked about this behind the scenes, that the the malware itself was actually pretty decent, you know, for you you and and this I think something that stood out about this is that um the the typosquats themselves inside of Ruby gems were kind of meh, but then the malware sitting behind it um uh you know was was more mature than we were expecting based on that initial part. So um I think that um the again this kind of you know looked and felt at a high level DPRK, not trading this to DPRK, um, but you know, the the endpoints and the ports used and some of those kind of high-level tradecraft bits felt kind of DPRK-ish, but you know, I mean that's not to say that other people aren't doing that, but you know, it was the kind of typical info stealer and um crypto stealer that everybody does now. Um uh I think it it had a couple of functions in it that specifically looked for credit card um strings in in files, which you don't see that often anymore. People don't really do that. Um that kind of that kind of um uh grepping through files looking for things like that are things that can get caught by you know even simplistic EDR um or or antivirus. Um so threat actors tend not to do it. But yeah, I mean that sorry, that's not like that not a super high uh quality analysis, but um it did feel to go ahead.
Jenn GileMaybe we can go through what the malware does uh because I think it's a little bit unique in that it uses whatever language the package started in, and then it goes into Rust, and then there's some Go in there. It's very specifically targeting Windows. So essentially it starts out with the victim installing the typosquatted package. Uh Ruby has a mechanism that's a little bit similar to what we've seen in NPM and in VS Code, where it can let you automatically do some a series of things without having an import or a require. So it's this uh extonf.rb. I'm not a Ruby person, so I don't know how you say that file name, but there's a special file name that essentially is kind of like an auto-install function. There's a hook from there, right? Yep, and then you know a couple steps down, it's looking to see, you know, it's pinging the host and saying, hey, what kind of operating system are you? Oh, Windows, hi, we'd like to, you know, stay here. Linux, mac OS, uh telemetry only and exits. But if it's Windows, then it downloads a Rust-based loader. Um and something that was very uh specific there is it's a 22 megabyte file size. So that 22, let's let's remember that and we'll come back to it. Uh again, it's gonna detect uh WSL, it's gonna bridge out to PowerShell, it's gonna launch a loader that's a Go-based info stealer, and then it's X filling a password protected zip file.
Paul McCartyYeah, let me jump out.
Jenn GileI'm gonna let you talk while I let my cat out of my office because he's he's not happy. So I'll be right back.
Paul McCartyYou talk. Yeah, I mean, uh in the meantime, I've been able to remind myself of what was going on here. I just see so many different attack chains, kill chains that they kind of all blend together. So I had to kind of remind myself. But I think um this was interesting because it did use like multiple stages. There's like five or six stages, and each one of those stages is actually written in a different language. So like the first loader, this 22 meg file, is is Rust, right? But then inside of it, there's an embedded Go uh second stage, and that's where the infostealer kind of kicks off. Um, but there's also JavaScript components and there's Ruby components. Um, and I think that that Rust loader with the embedded Go um info stealer in it is a pattern that we're seeing a lot from DPRK. And so that's one of those things that just kind of made me feel like, oh, this kind of could be there. But then there's a bunch of things that don't align with DPRK trade critics.
Jenn GileWell, like candidly, they are much better at typosquat targeting than what we saw with this campaign. And I'm not saying that means it's not them, but these were pretty bad.
Paul McCartyYeah, and and there's not, you know, you bad guys are gonna emulate other bad guys, and right so and the fact that the the point I was just gonna make is that it pulls that that 22 meg file from a GitHub repo. That's really unusual. Like DPRK traditionally doesn't want to pin and pivot off a specific GitHub repo because that's just something that I can kill the repo, it's gone, right? Yeah, yeah, and it's also something that I can sit there and I can watch, right? Um, so that was unusual. And the fact that they didn't hide the loader, it's just main.exe, right?
Jenn GileI'll also note that when we were looking at the object. Obfuscation, and I'm going to say obfuscation and air quotes uh IP address was kind of hilarious. All they did was take the periods out. So they had the bracketed IP address without periods and with spaces instead, and then with a join period after it. So, you know, anybody who's visually looking through there is like, oh, there's an IP address.
Paul McCartyYeah, you know, so like it's sending us these mixed signals, right? Like the IP address thing and like the fact that they're just sticking it clearly in a GitHub repo, the main loader, so it can get torn down. So here's a here's something to learn by bad guys. What you don't want to do is you don't want to make the first stage really easy to take down because then all the other stages don't run, right? You can you can get a little bit loose when you're down at stage four or stage five, but stage one you want to be hiding in. That's why DPRK uses things like ether hiding and null receiver in that second stage after the npm package of the GitHub repo, is because that's just that it's you know very effective at hiding and being letting them be able to iterate. But another thing that I just thought about, Jen, was that like the mixed signals that this attack was sending us, it actually had a pretty well done um uh bypass around the the Google Chrome app bound encryption um control, which I think surprised a lot of people. Like there are multiple people on LinkedIn and and Twitter, you know, mentioned oh, because we've only started seeing that um these bypasses recently, and other people are doing it, so it's not like this is super unique. Um, but what it does is it makes it that much more powerful in stealing stuff out of the browser, right? It's bypassing this significant control that Google added in like 1.127 or something. I'm sorry, uh version 127 a couple months ago. Um so yeah, all in all, mixed bag kind of looks like TPRK, kind of looks like vibe coding. Um, used all kinds of languages, right? And something I pointed out in my blog post is that this kind of casual polyglot, and if anybody's not familiar with this term polyglot, it basically means somebody that can speak multiple languages, or in this case, write multiple languages, use multiple languages. Well, people don't have to actually understand multiple languages anymore because Claude and Codex and whatever other agents they're using are writing all this stuff for them. So for whatever reason, they say, hey, write me a you know, follow the pattern from DPRK and write me a Rust wrapper, right, around the Go and then Better Go and or it's just following the patterns that it knows from the DPRK. Who knows? Very yeah, lots of mixed signals there.
Jenn GileWell, speaking of languages, uh, maybe two days after we published this research, I was in LinkedIn because I'm in there way too much, and I saw somebody's post about, and I'll quote, a 37-package typosquatting campaign on NPM. And so I always click when I see those kind of things. It was from somebody from Open Hack, and they in the initial description described a 22 megabyte Rust loader carrying an embedded Go info stealer. And I was like, ding, ding, ding. That sounds awfully familiar.
Paul McCartyAnd seems like a pattern I've seen recently.
Jenn GileYeah, yeah, yeah. That's that's very recent. So I took a second to compare it to your write-up. Uh, we pulled the payloads, it's identical. Um, the only difference being because it's npm and not Ruby, the uh firing mechanism is different. They took advantage of the npm post install scripts, which at this point are infamous uh in the community as a way to auto-install your malware. And then uh ultimately I found a total of 40 packages that were associated with the npm branch of this attack. Uh, the shape here was actually slightly different than what we saw in Ruby. Instead of these, as you say, country music name generator names, uh, it was five different uh NPM accounts that published the set of 40 packages. None of the names on these accounts are look like real human names for the most part. It tends to be a string of maybe 10 to 15 uh alpha characters or you know, letters, and then a series of numbers. Um, one of them is what is this app live 2023 8261? Another one is full basket property website 53a. Uh so very different in terms of naming conventions, but same deal with the really clumsy typosquats. They were um targeting Axios, chalk, commander, uh Lodash, and uh TypeScript. And there's probably, I don't know, 10 different TypeScript ones where they've transposed letters or added a letter and like it. I can see in some ways how somebody might, you know, fat finger the keyboard and accidentally type one of these things, but still it's a brute force style attack. Now, what I forgot to tell you, Paul, um, is one of the email addresses has some kind of like superfluous throughout the email address. And that's another thing that did remind me of DPRK because we've seen that uh in some DPRK NPM accounts where they'll have a username and then their email address is kind of similar, but has like random periods. Um weird. So we know for sure that it's hit two ecosystems. I was chatting with someone from the hacker news the last couple of days about it, and he emailed me last night and he's like, you know, have you seen it cross into any other ecosystems? And I was going to type no. And I haven't caught you up on this yet, so I don't know if you know what I'm gonna tell you. Um, and then I got tagged in a post overnight about the same campaign hitting PowerShell, and we haven't had an opportunity to take a look at it yet, but we're having multiple people say, hey, it's it's the same shape, it's just in PowerShell.
Paul McCartyYeah, and you know, the funny thing is I didn't even know that PowerShell gallery existed. I was like, oh my god, a registry for PowerShell. Yay! Add it to the pantheon of Microsoft things that are probably far too insecure. Um, so yeah, we have yet to kind of go down that road and we're going to.
Jenn GileUm, but I feel like I would say I have no reason to think they're wrong at this point. I'm seeing some screenshots in X. Um it probably is in PowerShell.
Paul McCartyI feel like I last night before I went to bed, I feel like I saw one come in um in VS Code or one of the other ecosystems that was labeled stub makers. So we're gonna we're gonna see these things. I mean, we typically do, you know, with many of these big campaigns that, you know, after the initial uh kind of wave, then we see additional stuff coming in. Um, so stand by. There might be some other ecosystems to add to that list as well.
Jenn GilePotentially in this campaign. And you know, as you and I talked about behind the scenes, we're not seeing the uh traditional hallmarks of AI written code, but uh that it was hitting the number of ecosystems that it seems to at the same time, and in some cases, you know, rapidly evolving, it seems possible, you know, given the number of different languages and ecosystems, like you said, nobody's expected to be an expert in I don't know, NPM Ruby, and PowerShell.
Paul McCartyYeah, I mean, the it makes sense that if you, you know, if you start out with an NPM or one of these high profile you know registries where things get taken down relatively quickly, you can take that same attack and just repackage it for some of these smaller, less, you know, with with less volume, less voluminous, anyhow, less popular or whatever ecosystems, repackage it there and maybe get you know some a longer tail out of it. So not surprising.
Jenn GileOkay. Last topic, uh, you've been telling me for a little bit now that you've been seeing an increase in what you're calling DIY binary payloads. So taking a step back, we don't actually see a lot of binary payloads in malicious open source. Typically, it's in an interpreted language. That's why things like hashes tend not to be very useful with malicious open source. Uh, you are seeing uh maybe like a little bit of a Frankenstein where some of it's interpreted and some of it's binary. So talk about what you're seeing.
Paul McCartyI mean, Stub Maker is the perfect example. This is a great segue from the Stub Maker conversation here, where Stub Maker had you know five or six languages used in binaries in at least uh three languages, C Rust, and Go. So basically, yeah, I've been saying on the podcast and other places for years that like, you know, I I have I don't have to do a lot of dynamic or or sandbox analysis because most of the stuff we look at is interpreted. And as long as you have a built-for-purpose static analysis harness, you know, you can kind of you know take care of 99% of it. But just in the last two weeks alone, I've just seen the increase in software supply chain attacks that are using you know binaries in stages two through four or whatever, has just increased dramatically. And I've just spent a lot of time over the last two weeks doing stuff that I typically don't have to do, you know, reviving some of these skills from my heyday. But um, I think this is evidence of a couple things. I think it's evidence of first the use of agents and LLMs to write or help write your malware. Two, because you're not a mature uh uh open source malware or software supply chain malware writer author, the way that you think that you have to hide your malware is by putting it in a binary and kind of following that traditional path, right? So you're new, you're like this newbie malware author, and you're looking at you know, like VX Underground and this whole thing that tells you that you got to build uh binaries to hide your shit, your stuff, and that's what you do. That's the pattern that you you follow, right? Um I and I think the reality is those stick out like a uh like a sore thumb. When you see a npm or RubyGems package installing a binary, either with that binary in the package itself, which makes it bloated, right? As we were just talking about with Stunmaker, or downloading that, immediately downloading that from a URL or an IP. I mean, these are pretty big flags. So you might think that you're hiding it in the binary, but the fact that you're adding the binary itself is the biggest red flag. So uh tip all school malware.
Jenn GileYeah.
Paul McCartyI'm gonna I'm gonna give you bad guys a little tip here, which is you you don't use binaries, they like you think that they're helping you and they're not, right? Dum dums. Um, anyhow, we'll leave it to that. I um I also wanted to throw in classic YOLO style. I also want, and I think this is probably something we can talk about more next week, but Jen and I have been seeing the number of people affected by Pollen Rider like being reinfected. Just I was checking that that GitHub community.
Jenn GileI meant to tell you, I'm I am subscribed to updates, and uh I was gonna read this one.
Paul McCartyUh I think uh after I took a screenshot of it for exactly that purpose too, as well.
Jenn GileAfter nearly two months of inactivity, the malware has started pushing changes to all repositories and branches again. Womp womp. That's my ad. Womp womp is me. Um they found that it's using you know an Ethereum address. Uh it's that same reinfection cycle that we've been seeing.
Paul McCartyInterestingly enough, this is the first time that we've seen null receiver used in well, actually, that's not true, right? I think we have seen null receiver in the pawn rider, but it has not much, right? So this is clearly the use of null receiver at stage two um in to replace ether hiding. In fact, this kill chain, um, you know, when we initially saw null receiver at stage two, which is basically hiding the IP address for for the next stage in um in the uh response, uh the destination response, which didn't exist. Um, we saw ether hiding in the next stage, right? So there was no receiver and then there's ether hiding. We don't see that anymore. Ether hiding is gone, uh, and it's been replaced by no receiver. And so this is Pollen Rider, DPRK, is now using null receiver as a primary hiding methodology uh instead of ether hiding. So, you know, gone are the days of ether hiding.
Jenn GileHow is this possible conversation? You know, you've got a person here in the GitHub community saying uh they, you know, of reading between the lines, they think they got rid of the malware. Two months later it's back. How does this happen? Um, how is DPRK pushing updates? How are they, you know, putting in new parts of their kill chain? Because obviously null receiver wasn't there two months ago. Um, this comes back to the way that Paul and Writer works from a basic level is this is not a threat actor, you know, using your credentials 100% of the time, hanging out on your machine. So, like maybe you have rotated your credentials, maybe you've even replaced your machine, but you go and you know, accidentally reinfect yourself uh using your repo, or the other way around, it's still hanging out on your machine. It's able to get whatever credentials you have locally. And the I guess brilliant part about this malware is it can make commits to your repo without leaving a trail. So you won't see a suspicious commit necessarily. Sometimes you will, but um, sometimes you won't see a suspicious commit at all. Uh, they're able to hide that so that you can't just have an alert set up that says, hey, let me know if something new comes in here that I didn't authorize.
Paul McCartyYeah. I mean, to say this a different way, what we hear again and again and again from these victims is that they're looking at their commit history in GitHub and they are unable to reconcile in a brain because they just don't understand how it works. How they're looking at a git a commit history that hasn't changed or it doesn't appear to have changed, and yet they're looking at a file and there's a new malicious payload there. They just can't comprehend that, and that's because of one thing. And the funny thing is that there's usually like an engineering uh misunderstanding or uh or an uh infosecse ops misunderstanding. In this case, both of these you know personas don't have an understanding, which is that the git commit history happens on your machine. GitHub just expresses that as a luxury to you, right? It just accepting the git commit commit history that's coming from your machine when you push up to origin. So what happens is dprk is overwriting existing older commits three years ago, five years ago, ten years ago, doesn't matter. They overwrite those, put the new malicious payload in there, then they wait for you to go ahead and do your work, and then you push it up again. And here's the other thing, and this is uh continuing our YOLO trend. Uh, DPRK has now found a way to infect NPM itself, the package manager. We will talk about this next week because we got to do a blog post about it. But the reality is that DPRK is ever innovating in this space, and that's why Pollenwriter continues to be this just massive human bot network that keeps infecting people. So they buy a new MacBook and they set it up and they're infected within a day or two. So it's crazy.
Jenn GileUh, on that note, uh, we've got one more podcast this month. Uh, we're gonna take a week break, and then Paul and I will be in Europe uh in early September. We're gonna be in uh Strasbourg for underground economy. So come say hi if you're going to UE. And then Paul, you're gonna be speaking at B sides which one?
SPEAKER_00Frankfurt.
Jenn GileFrankfurt. B Sides Frankfurt. So if you're gonna be at either of those events, come say hi. Let us know you're gonna be there, whatever. We'll give you a sticker. We'll talk about Paul and Rider. I think we're talking about Paul and Ryder at both, right? I assume that's what you're presenting in Frankfurt.
Paul McCartyYeah, yeah, we are. Yeah. So uh uh UE is September 7th through 10th. And Frankfurt B size is September 11th. I can't forget that day. It's September 11th. So that's gonna be um that's gonna be an interesting thing to talk about, you know, in Frankfurt on September 11th.
Jenn GileYeah. All right, everyone, have a good one. This was a little bit longer than usual, but lots of interesting stuff to get into.
Paul McCartyThanks. Thanks for listening, everybody. Appreciate it.
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Open Source Security
Josh Bressers
Future of Threat Intelligence
Team CymruAbsolute AppSec
Ken Johnson and Seth Law
Coffee, Chaos and ProdSec
Cameron Walters and Kurt Hendle