The OpenSourceMalware Show

TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts

OpenSourceMalware Season 1 Episode 19

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 30:55

This week we talked about: 

  • TeamPCP arrests — Australian Federal Police and the FBI arrested Ruben Thomson (21) and Louis Gaebler (23) in Perth on TeamPCP-related charges. The arrests align with the OpenSourceMalware team's longstanding assessment that TeamPCP was a very small operation, effectively one or two people, despite the scale of its attacks. Krebs' reporting details the OPSEC failures (reused usernames and passwords, prolific unredacted social media activity) that led to their identification, and despite the technical complexity of the attacks, the financial payout was reportedly modest (around $20K). Jenn and Paul discuss what this could mean for other overlapping threat groups like Lapsus$ and ShinyHunters.
  • PolinRider's persistence outlasts partial remediation — A look at how DPRK's PolinRider campaign continues to reinfect developers who believed they'd already cleaned up. When a developer only removes the malicious payload files but not the underlying persistence mechanism (like a vscode-task.json trigger) or the RAT running on their machine, DPRK can push new payloads that ride along on the developer's own legitimate package publishes. Paul and Jenn cover what's changed in the kill chain: a new NullReceiver-branded payload, a persistence technique that overwrites the npm CLI binary itself so simply removing payloads from repos isn't sufficient, and an expanding target list of JavaScript/TypeScript file types the malware will inject into. They close on why disclosing an infection to collaborators matters, since silent individual cleanup doesn't stop reinfection through shared repos and contributors.

Episode resources

TeamPCP:

PolinRider:

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

Open Source Security Artwork

Open Source Security

Josh Bressers
Absolute AppSec Artwork

Absolute AppSec

Ken Johnson and Seth Law
Coffee, Chaos and ProdSec Artwork

Coffee, Chaos and ProdSec

Cameron Walters and Kurt Hendle
The Secure Disclosure Artwork

The Secure Disclosure

Mackenzie Jackson