The OpenSourceMalware Show

Live from Strasbourg & Underground Economy

OpenSourceMalware Season 1 Episode 20

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 46:42

Jenn and Paul also mark OpenSourceMalware's first anniversary, now tracking close to 200,000 verified threats and over 100,000 IOCs. We also discuss:

  • Mini Shai-Hulud payload resurfaces on npm. A payload from May's Mini Shai-Hulud campaign against AntV reappeared in four packages published within the same hour on September 7th, sitting undetected for 111 days despite npm's publish-time scanning. 
  • Q&A from the Underground Economy conference. Reporting live from Team Cymru's conference in Strasbourg, Jenn and Paul answer the questions they fielded all week: whether DPRK and Russia collaborate on supply chain attacks, why malicious open source rarely targets specific countries, whether North Korea needs AI to close a skills gap, why GitHub allows git history to be rewritten and hasn't done more to stop PolinRider, and what developers can realistically do to protect themselves, since PolinRider's payload runs regardless of what language a repo is written in.

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

Open Source Security Artwork

Open Source Security

Josh Bressers
Absolute AppSec Artwork

Absolute AppSec

Ken Johnson and Seth Law
Coffee, Chaos and ProdSec Artwork

Coffee, Chaos and ProdSec

Cameron Walters and Kurt Hendle
The Secure Disclosure Artwork

The Secure Disclosure

Mackenzie Jackson