The OpenSourceMalware Show
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.
Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.
OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more.
https://opensourcemalware.com/
The OpenSourceMalware Show
TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This week we talked about:
- TeamPCP arrests — Australian Federal Police and the FBI arrested Ruben Thomson (21) and Louis Gaebler (23) in Perth on TeamPCP-related charges. The arrests align with the OpenSourceMalware team's longstanding assessment that TeamPCP was a very small operation, effectively one or two people, despite the scale of its attacks. Krebs' reporting details the OPSEC failures (reused usernames and passwords, prolific unredacted social media activity) that led to their identification, and despite the technical complexity of the attacks, the financial payout was reportedly modest (around $20K). Jenn and Paul discuss what this could mean for other overlapping threat groups like Lapsus$ and ShinyHunters.
- PolinRider's persistence outlasts partial remediation — A look at how DPRK's PolinRider campaign continues to reinfect developers who believed they'd already cleaned up. When a developer only removes the malicious payload files but not the underlying persistence mechanism (like a vscode-task.json trigger) or the RAT running on their machine, DPRK can push new payloads that ride along on the developer's own legitimate package publishes. Paul and Jenn cover what's changed in the kill chain: a new NullReceiver-branded payload, a persistence technique that overwrites the npm CLI binary itself so simply removing payloads from repos isn't sufficient, and an expanding target list of JavaScript/TypeScript file types the malware will inject into. They close on why disclosing an infection to collaborators matters, since silent individual cleanup doesn't stop reinfection through shared repos and contributors.
Episode resources
TeamPCP:
- (news) Two WA men charged after investigation into alleged cybercrime
- (official) Two WA men charged following AFP FBI WAPF disruption alleged global cybercrime syndicate
- (news) Two Alleged 'TeamPCP' Hackers Arrested in Australia
PolinRider:
It is Thursday, August 27th, and we are here with I'm going to call it breaking news out of Australia, which maybe is not a thing that we hear too often in the cybersecurity world. But uh good news. The Australian federal police arrested two individuals associated with Team PCP. Um they're two of the more uh perhaps active members, from what it sounds like. And Paul, love to hear your side of this in just a second. But just in brief, um, it's a 21-year-old and a 23-year-old. Uh Ruben Thompson and uh the other suspect was identified by ABC's court reporting to be Lewis uh Gabler. Uh you know what can I say? It on one hand, play stupid games, get stupid prizes, uh F around and find out. But also um these are two incredibly young people. Uh one of has a history of drug abuse and employment problems. The other has gotten involved in some pretty nasty neo-Nazi stuff. Uh honestly, as a parent, I hate to see two young men having gone down this path. I hope that whatever comes next for them uh gives them an opportunity to decide to do something different with their lives. They're young and they have a lot of life ahead of them, hopefully. And I hope they've learned from this.
Paul McCartyYou are like you and I are just so different in this regard. Like we're both parents, right? And so I think that's an important thing to, but I am just so like I have no sympathy for them. They're drug addicts.
Jenn GileWhat they did was incredibly wrong. But these are also like it's sad to see. This is not your like hardened criminal uh life of crime kind of thing. Like, these are, as we've been talking about for several months, a couple of like kind of dumb kids.
Paul McCartyYeah, and I think that that's gonna be the theme running through today's show, which is just dumb kids. They just did a bunch of dumb stuff, which we knew uh we were calling out before they got arrested. But um, I think uh one take on that last part or that first part there before we move into the the heart of today's conversation about these guys, is that listen, I understand they're at the beginning of their lives, but they also come from what appear to be relatively well-off parents. They seem like mostly useless drifter type people. Like, listen, I was a I was a 20-year-old man, right? That was trying to figure out you know where I was. And you know what I did is I found I found a passion and I followed it and I became successful, right? So I don't have I don't, I don't no.
Jenn GileUm maybe I'm giving well, no, I don't disagree with you because you know, I was reading uh Brian's Kreb, Brian Krebs article in detail, and I found Ruben Thompson's general attitude about the job industry to be on one hand, understandable because getting into cybersecurity is not easy, but on the other, he acted like he didn't see an alternative. And I just I have a tough time with that. You know, I know a lot of people who work hard to get into cybersecurity who have the same uh barriers that he may have had. Uh, you know, they talk in the article about, you know, if you don't have experience, employers won't look at you. There are a lot of ways to get experience.
Paul McCartyWell, you know, bad people like to latch on legitimate arguments like that to make to validate why they did what they did. And let me just start out by saying something super crazy, which is Jeffrey Dahmer, before he killed his first person, could you know it was just a 20-year-old man who hadn't done anything, right? And you know, the innate evil within him. And these two guys, I got I got no sympathy that well. I know you we neither one of us has sympathy for him, but I um I hope they throw the book at him. Um, not only do I hope they throw the book at him, um, these two young kids are just gonna, even in Australian prison, because both of them are white supremacists. That's the other thing you have like they both one of them, Casper, is more out there, but you look at some of the things that that old mate Ruben has said. He comes from South African, he comes from a he comes from a I don't think he comes from a Boer background, but I think he comes from an Anglo background in South Africa and is very um, you know, entrenched in that kind of white supremacist, Anglo-nationalistic.
Jenn GileAnd yeah, they've said some pretty nasty things.
Paul McCartyIt's there's a there's there's this growing movement, and I don't want to give it too much play here, but there's this growing movement called re migration, right? Which is just a fancy word for racist white supremacist nationalists, and there is some overlap. Um, last night a um a journalist was pinging me some stuff about some of the remigration things happening here, and there's a connection between that and some of these like South African folks. Um, anyhow, more to be discussed later on. Let's jump into the heart of this, Jen. Let's get her on.
Jenn GileWell, so where do you want to start with it? Because uh there's plenty to discuss from the Krebs article, from the uh AFP uh press release. I know you have been uh talking to people behind the scenes for multiple months, I want to say. Uh, so you you know kind of knew this was coming. Um what do you want to discuss?
Paul McCartyYeah, I mean, I like uh, you know, I was preview to some inside baseball. Um, you know, and I don't want to go into a lot of details because I don't want to, you know, I don't want to be part of inside baseball in the future. Yeah, you know, I want, but but the reality is that um I had some intel that you know one of these people was perhaps in my country, um, and um, you know, some meetings took place because of that. But um, I think the first thing I want to say start out by saying is that listen, we were right, we called it, right? Like basically, team PCB is one guy, Ruben Thompson, right? 21-year-old from Cotaslo, outside of Perth. It's a it's a well-to-do suburb in Perth. Um, he is South African, so all that intel about the South African part is true. And you know, like this is what happens. You said it earlier, f around and find out, right? Like, they they prodigious posting on Twitter and Telegram and all kinds of other places. Didn't terrible reusing the same username and the same stupid password, like Krebs just like the Krebs article is just brutal and it's efficient. Oh my god, it's just like brutal and it's efficient tear down of how stupid these I can't say any cuss words, but I really want to say that dip word. Um, they just uh it's just morons, right? And I think it's hard for us to reconcile the fact that they are so stupid and made so many mistakes with the fact that their attacks in March and April and May were pretty complicated. I mean, and yes, they were barring heavily on the original Shy Halud threat actors and you know, barring from the ecosystem, but you know, it was effective because you know it was it it attacked a place where not a lot of people really kind of understood what was kind of happening. And we talk about that in that the interview that we did with with Akido and Socket and all those guys. The fact is that we all many of us use GitHub actions every day, or the equivalent, just to be clear. And there's just a lot going on there that we don't really kind of talk about. There's just a lot of containers and stuff going on. Then they took a they took advantage of that, right? And they were very effective. They don't they weren't able to actually make any money. My understanding is they made about $90,000.
Jenn GileLike it just well, the the Krebs article says that Thompson made like 20k. So yeah, yeah. I mean, not sophisticated. Uh, I think this is a great example of how an LLM can get an unsophisticated bad actor further along than they would have been, but it can't make them. I mean, let's go back to our uh terminology from North Korea. You know, it doesn't build a go-to-market for them, it doesn't build a business for them. You know, they you have to know uh how to do targeting and how to take advantage of the data that you get a hold of. And so the good news out of this is they're not, you know, terribly smart about what they did collect. Um, let's just hope this is the last we've seen of this.
Paul McCartyWell, yeah, and let's talk about that for a second. Um, my understanding is that there's a lot more to come. Now, and and uh that when so what does that mean?
Jenn GileYou mean around the um not coming, but more more people getting in trouble or out in law enforcement activity.
Paul McCartyAnd here's the thing is that uh, you know, aside from exploiters who still is in the wind, um team PCP has been wrapped up. So, what is there more to do about that, right? Like I called it, you know, this basically I was saying team PCP was like one guy, maybe a second helper, and that's exactly what we have here. Um, you know, are there some other people ancillary around them? Of course, yeah. Like in Colonel Stub right now is out there just you know talking about how they turned themselves in and all this other shizzle. But um, the reality is it was relatively small. Yeah, oh my god, so many people like being oh, I was in the know, and oh just god, some of the most toxic personas on Twitter, but um, which is the right place to be toxic. Um, but the point I'm driving at it here is is an important one, which is if there's more to come, and team PCP has effectively been wrapped up with a few threads hanging out there. What are we what what's coming? And my expectation is that there is going to be movement against lapses and shiny hunters and some of these other groups because there's enough overlap between some of these groups where um, and I I I want to hope meet Francois. You know, I'm I'm talking about you, buddy. I'm hoping that something that what France Francois and I worked on um ends up um doing some good out there, but um uh you know, I think the reality is that um there are gonna be more arrests, there are gonna be another cruise, and um there's gonna be kind of this domino effect. Sorry to use these cliche terms, but there's gonna be a domino effect here where like once you get that much data from somebody because they've already pulled like I heard in one of the things a hundred terabytes already off of old mate Rubin's machine. Um, and you know, as everybody knows, they stole uh just a ton, absolute ton of credentials. So, you know, just a lot of there's a lot of gold there. And based on the rest of their opsec, I'm gonna guess that all this data was just sitting on their hard choice. The AFP now has uh and big shout out, by the way, to AFP. Um, not that they get back to people when they turn anyhow, but um the that aside, uh big shout out to AFP for working with FBI to to do this takedown. Um, so good on them.
Jenn GileYeah, good news today. Okay, let's talk about it.
Paul McCartyToday's a good day, Jen. Today's a good day. Today's a good day. We you and I have been talking about this day, like we literally have been talking about this happening for a while now. Like we knew it was happening, we just were waiting for the vaccinations to go through, and and here we are. It's happened. Team PCP is is effectively been taken down. That's awesome.
Jenn GileYeah, very happy about it. Um now let's talk about our favorite subject. Uh and I only say that because I think we do talk about this just about every podcast, but that's because we're always finding new things. So, this is what's going on with Paul and Writer. Um, we are preparing to do a talk in what, a week, week and a half. Um, and so we've been preparing for that and doing some extra hunts and found some interesting new things. Uh, some of it is more like reinforcing that it is bigger than what the data was initially showing. Some of it is showing it went back further than what the data initially showed. Um, we published a blog, I'll share the um link in the comments that uh goes through a pretty interesting case study of a person who got uh, I won't even say reinfected because they never cleaned out the infection to begin with. But they got infected, they thought they cleared it out, uh, it has been pushed into their packages. So um maybe maybe let's start there and then you can open up into the broader hunt that you've been doing.
Paul McCartyYeah, I mean, at the heart of this is the fact that you just have a lot of developers um that have been compromised over the last couple of years. Contagious interview from DPRK has been going on since 2023. A lot of people are compromised. The problem is that what we didn't really kind of talk about as much as we probably should have is the fact that the DPRK maintained persistence on these developers' machines. Um and that is rearing its head now as all these compromised GitHub users, they're compromised on their local machines. Their GitHub accounts aren't necessarily um uh compromised, but they're compromised on their local machines. So the persistence is happening on their local machine. And uh what we're seeing now, we we talked about this a couple episodes ago with with Go. We every day we see a new smattering of Pollenwriter in Go packages because Go doesn't have an additional publish step like NPM or PyPy does. But we are now seeing Pollenwriter in PyPy, we're seeing it in NPM, we're seeing it in VS Code, we're seeing it in other places. As these developers you know go about their daily business and they go to deploy a new npm package or new PyPy package or whatever, the Pollenwriter malware slides through and inside of that new thing. So in this particular case, the fetch page assets and HTML to Gutenberg maintainer, um Diogo was compromised. And you know, npm took down version whatever dot nine of of um fetch page assets, but then immediately he published dot 10.11.12.13. These are all legitimate pushes by the real um, or actually, in those cases, Jen, I think that might have been DPR.
Jenn GileNo, they're all well, okay. Let's rewind a little bit. So Diogo is a legitimate developer who got compromised. Uh, we don't know specifically how he did, but probably given his um profile of like an independent developer, is probably through Contagious Interview. Um, it looks like it happened maybe around January of this year. And um the way that this particular piece of malware works is yeah, it's on your machine, but then it looks for places that it can inject its payload and then pushes them to your repos. And so that's what happened is through his normal CI processes, uh infected files were pushed into all of his repos. And then because two of those repos serve um as source code for two corresponding NPM projects, when he pushed updates to those npm projects, new versions, the malware came along for the ride. And uh that malware was discovered a few months ago. It got taken down relatively quickly. Um he went through some remediation steps. We can see evidence of that where he deleted the files that had the payloads in it, but he only did a partial job. He didn't delete the VS Code task.json files that were triggering those payloads. And we can assume he also uh didn't properly probably clean his machine and we can look through his repos and we can still see evidence of infection in his repos. And whether he continued to push new versions or the threat actor, I would say it's probably him. He probably, you know, was making updates to his packages. We can see this series of you know updates coming out over the last couple of months where he pushed a new version because he wanted to, you know, have a non-malicious version. And then the threat actor was able to push a new uh payload onto his machine. And that is through the the wrap that is undoubtedly on his machine, which then trickled its way back into his packages. And so May, I think, is when those original poisoned packages were published. They've each had a few versions come out since. They are all malicious. Uh and I think the thing that surprised us was that nobody has caught this. These this was a known compromised developer. Uh two known compromised packages. Not only did we not catch it, um, you know, we'll own our own thing here, NPM didn't catch it, which certainly I would have hoped that they would have, since he should already be on their radar. But as you talk about in your blog, they're focused on the package as the important data point, not the individual. None of the other scanners seem to have picked it up either. So he has had this persistent infection for several months that has had evolved payloads. So no fun for him.
Paul McCartyYeah, I and I think the timeline is important because each victim is a little bit different because what happens is the infection starts on your local machine via um a malicious git repo that gets the payload gets run from VS, typically from VS Code using the task function. Sometimes there's other alternative ways. There's sometimes there's a git hook, and other times you you run the app, and when you run the app, it actually runs some system commands. There's a number of ways, but most of the time it's VS Codes. So you're compromised on your machine. And then what happens is that allows North Korean threat actors to manipulate files on your machine, they have access to your disk, and what they do is they go and look for all the git repos that you've got, which you said earlier, and they find ones that match what they need, and then they push these payloads in. Now, the second part, this is where things sometimes change. If they have if North Korea has access to your credentials, because when the info stealer that was part of that rat and part of that kill chain, when the info stealer runs, if they get access to your Git um account via a pat or some other function, then what they do is they will then push. And so in Diago's case, there were pushes that our system identifies as non-human. So basically, what happened is DPRK orchestrated changes on his local disk to files that were inside of the Git repo. It then also orchestrated the push of those out, you know, basically overwrite a commit and then push it out to GitHub. So those two things both were automated by DPRK. The third thing, which was not automated, which is the publish of the npm package. Those were always Diogo himself doing those as part of legitimate work. He just didn't realize that his GitHub read repo that was building the NPM package had this, you know, persistent payload sitting on top of it. And DPRK pushed three additional payloads into the Git repos. So the last one wasn't that long ago, it was just a few days. Well, about a week ago now, but and that last one is null receiver, it's the latest version, it's got a brand new campaign marker. It's the best. And that's the problem with this is that when DPRK has access to your machine and can and has a rat running there, they can keep pushing new better payloads.
Jenn GileI mean they're helping you out, they're giving you updates, right?
Paul McCartyThey're giving you the wrong updates. Wrong updates. You want to pin their old version of their old malware.
Jenn GileWe've been mapping uh their persistence mechanisms, and there's at least four separate persistence mechanisms related to this campaign. Some of it's in the original kill chain, some of it's Pollenwriter specific, but there is a new one um that somebody in the community surfaced maybe a week or two ago, where they have now added a step in their kill chain where they overwrite the npm CLI with a malicious version of the CLI. That's a particularly nasty one. So even if you clear off everything else that we've been talking about for months, this little malicious npm CLI, the next time you fire up npm, we'll say reinstall malware, and it just kicks off the whole thing again.
Paul McCartyIf you if you find the the Python or the JavaScript persistence, the rat and you kill that and you find where it's starting from, from a bash RC file or an NPM RC file or wherever it is, if you kill that, if you get it out of there, if you know if you go and look and find all the payloads and all your git repos and get rid of those and actually remove them from your git index, because just pushing a new version of it doesn't mean that the payload's gone. It just means you've got a new version that doesn't have the payload. If you do all those things alone, but you don't uninstall or delete npm, you're gonna get reinfected because the next time you run npm. NPM. It's so basically the normal size of NPM, which by the way is just a NPM CLI is just basically a bunch of like um simlinks to different JavaScript files, most of which end up in a uh in a CLI folder inside the NPM. Anyhow, it's crazy. Why would you do that? But it's JavaScript. Um, they overwrite that 200-byte file with a file that ends up being something like a thousand K or something. Yeah, I think it's big as well. I think it's I think it's 1100K or something like that. Um, but it's and and some people, you know, we didn't even do this. Some people out there in the open in the wild have created tests um for some of this stuff. So and and we've pulled that into our blog and also shout it out to them too as well. So there's some really simple things you can do to look at the size of your npm file, for example. Um, just make sure you're following the simlinks. So if not, then not gonna work.
Jenn GileYeah, the other thing that you said you've been observing is um so there's two kinds of files that this malware will create on your machine or modify on your machine. We've talked extensively about the task.json files. We are still seeing um lots of ones that are config files, JavaScript or TypeScript config files. And Paul, you said that initially they tended to save those in index, but now you are seeing them all over the place that they're just spread and it's not, you know, three or four different types of files. It's really just any kind of config. Talk a little bit more about what you've been observing.
Paul McCartyYeah, good call out. Um, so in the original version of Pawn Rider from from March of 2026, um, basically what happens is in that in that part of the kill chain where their malware is going and looking for JavaScript files to write into, it was only looking for five or six files wite.config.js and and you know babel.config.json and just a very small number. And then that number grew over the next couple of months, and you know, they were looking for like 15 or 16 different files. And if they find that, they would just append their payload on the end of it. Well now they're just looking for any JavaScript file. Any and what what they're also doing, Jen, is they is they're looking for files that are actually getting used as part of the execution order for that particular project. So that's what's smart about it, is that they don't just go and find some like random JavaScript file. They basically look at the code and really briefly take a look at kind of how that how the call um process works, and then they find a JavaScript file that's actually gonna get called and they drop it into there. So reachability. Yeah, exactly. It was really, really well. I it's very simplistic reach of reachability. But that's funny. Um but uh so we're seeing it now in all kinds of stuff. So basically, this is one of the things, this is why our hunt keeps growing is that you know we had that original five or six files they were looking for, then we had like the 10 or 8 or whatever, and then it was grew and grew. And now we just look for any types, types, any here's the extensions you want to look for.js, obvious. Um, excuse me, dot TS TypeScript also probably should be uh obvious. Then all the minified in the the the um uh the ESM and common uh JS files, CJS, mjs, and that whole kind of thing. So there's like five or six extensions you want to look for, um, which means that your searching now is gonna be you know longer. It's gonna be more, it's gonna take more time because you're looking through a lot more files, but you know, that's what you got to do. And when we're doing that now in GitHub out there forward hunting, we're just finding a lot more files. I pushed like, I don't know, 1200 or 1400 new GitHub repos to OSM just yesterday, one day.
Jenn GileUm, you said something that gives me an opportunity to get up on my soapbox, and I know you're gonna join me up on it. Um, because this takes so much time, uh, this is not just about like cleaning your own stuff and worrying about yourself for every minute, hour, day that you're going through incident response. If you have public repos, if you're collaborating with anyone, uh the infection is spreading to your network. And I know that disclosures suck. Nobody likes to do that. But if you found that you've been infected, uh, please, please, you know, disclose. Tell people in your network that you know are collaborating, not just because it's the right thing to do for the community, but if you clean out all signs of infection and then you're still collaborating with people who are infected, you're just gonna get reinfected. So if you don't give them the opportunity to look for signs of compromise and address it, you're hurting yourself in addition to them.
Paul McCarty100, oh my god, great call out. Um, and we are see we are genuinely seeing that. So people they they say, oh, some, you know, like for example, I'm automating disclosures now into open source projects that we find Pollen Rider in. Well, basically, we have an automation thing that goes out there and drops an issue into the GitHub issues for that particular project. What'll happen is they'll see that, then they'll remove it from the GitHub repo and they won't say anything. They'll close the issue and they won't say anything, right? But then the problem is that somebody inside one of their contributors and maintainers, or sometimes multiple, uh, will still be infected on their laptops and the whole thing will just come back. And we've now seen that with some of these open source projects where it started out as one or two people inside of the contributor group had it, and now they're all infected. It's like COVID, except you can't build up an immunity, you can just get it immediately again, right? So um, to your point, I think we need to do a lot better at just saying, hey, listen, I got hacked. Um, and here's what you know, here's what we did. We suggest you do the same thing, and here's the things to look for, and reference our that great um blog post that you put together, Colin Rider for for developers.
Jenn GileYeah, thank you. I'll drop that link in the chat. I put together a little incident response remediation guide. Um you know, this conversation. Um, hold on, I can type and talk at the same time, I swear. Um this reminds me of you know, the whole there's two kinds of companies, those that have been compromised and those that don't know they've been compromised. I think we're you know, this is this is a similar thing. Um, this is spreading widely, it's evolving rapidly. Um the signals are constantly changing. You know, we're constantly updating our own internal detections because what was reliable weeks or months ago is no longer being used or not being used as widespread. Um, so yeah, I guess this is a plug for having some intel on PollenWriter so you know what to look for, but start with the blog that I wrote because it'll at least give you some places to look for.
Paul McCartyExcellent, excellent advice. I have nothing to add. Nothing to do with that.
Jenn GileOkay, let's wrap it there. Um as a heads up to our dedicated listeners, of which there are some, which we love. Um, we are gonna take a break next week for a little much needed uh vacation time slash family time on each side. And then we're gonna figure out when, how, where to record an episode while we are in Strasbourg. Um coming up uh in the first week of, or I guess second week of September. So very much looking forward to another uh live from the conference, Jen and Paul talking about what we've uh been experiencing, learning, etc.
Paul McCartyAnd hopefully I'm not sick this time.
Jenn GileYou're not gonna be sick this time, you're gonna be so healthy.
Paul McCartyUm my my immune system's all jacked up now. Um yeah, just to kind of double click on that, we will be in Europe uh September 6th to 11. Um uh seven to 10.
Jenn GileUm, yeah. Oh, sorry, the conference is the seventh.
Paul McCartyYeah, I'm also gonna be yeah, I'm gonna be there September 11th too as well. I'm actually talking at uh I'm actually sorry, I'm giving training on GitHub CTI stuff at uh Frankfurt B size on the 11th. I'm having dinner with some friends the night before, so I'm really looking forward to this. Um, so yeah, if you're gonna be in Frankfurt or Strasbourg um for whatever reason, let us know. We have a lot of users in Europe, so we have a disproportionate number of OSM users in Europe. So come out and say hi.
Jenn GileOn that note, have a good one.
Paul McCartyYeah, thanks for listening. We really really appreciate it.
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
Open Source Security
Josh Bressers
Future of Threat Intelligence
Team CymruAbsolute AppSec
Ken Johnson and Seth Law
Coffee, Chaos and ProdSec
Cameron Walters and Kurt Hendle