The OpenSourceMalware Show
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.
Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.
OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more.
https://opensourcemalware.com/
Episodes
20 episodes
Live from Strasbourg & Underground Economy
Jenn and Paul also mark OpenSourceMalware's first anniversary, now tracking close to 200,000 verified threats and over 100,000 IOCs. We also discuss:Mini Shai-Hulud payload resurfaces on npm. A payload from May's Mini Shai-Hu...
TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts
This week we talked about: TeamPCP arrests — Australian Federal Police and the FBI arrested Ruben Thomson (21) and Louis Gaebler (23) in Perth on TeamPCP-related charges. The arrests align with the OpenSourceMalware tea...
Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads
This week we talked about: Rust arrayref compromise tied to DPRK infrastructure: A compromised maintainer account published malicious versions of the arrayref crate, along with internment and append-only-vec, adding a typosqu...
Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft
This week we talked about: Hacker Summer Camp trends. Jenn and Paul share observations from Black Hat, DEF CON, and BSides Las Vegas last week, including a maturing AI security conversation that has shifted to foc...
New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation
This week we talked about:New npm worm hits Keyv and cacheable. Jared Wray's GitHub account was compromised on Tuesday, and threat actors used it to publish a worm based on the open-sourced Mini Shai-Hulud malware. The worm s...
Hugging Face update, GitHub security improvements, DPRK linked to chald/debug, and more new PolinRider research
This week we discussed:Update from Hugging Face: Hugging Face published a technical timeline of the OpenAI evaluation agent that breached its production infrastructure between July 9 and July 13, reconstructing over 17,000 attacke...
Hugging Face incident, AgentBaiting, RubyGems, CrashStealer, and new PolinRider research
This week we talked about:Hugging Face breach and OpenAI's rogue model claim — Hugging Face disclosed a breach with thin details; OpenAI followed up claiming one of its models caused it during an internal security test...
Dependabot cooldowns, Jscrambler and AsynchAPI compromises, new PolinRider research
This week we talked about: GitHub turns on Dependabot cooldown periods by default — A three day cooldown is now applied automatically to all Dependabot version updates, a shift we've been anticipating in the fight...
Open VSX security improvements, new PolinRider researcher, shady vendor practices
This week we talked about:PolinRider jumps the fence — Paul's research on North Korea's automated repo-hijacking campaign spreading into the Go and PHP ecosystems without any extra effort from the threat actorsCyb...
GitHub security improvements, shady vendor practices
This week we talked about:GitHub’s two new account protection features: NPM added a 72-hour read-only lockout for high-impact accounts triggered by an email change or 2FA recovery code use, aimed at slowing account takeov...
How malicious OSS is evolving in 2026, feat. DPRK innovations
This week we talked about:DPRK Lazarus Group trends in software supply chain malware: Three active techniques he's observing from North Korea's Lazarus Group. The first is “version sandwiching,” where threat actors publish benign ...
Mastra compromise, agentjacking research, busting malware myths
Mastra Package Compromise: Threat actors hijacked the entire Mastra npm organization (116 packages) after a maintainer was targeted with a ClickFix-style attack that stole his credentials. Rather than injecting malware directly into Mast...
MSFT hit by Miasma worm, VS Code cooldowns, npm v12 breaking changes
Miasma Worm Hits Microsoft — On June 5th, 73 Microsoft GitHub repositories were disabled in 105 seconds after being compromised by the Miasma worm. Four GitHub organizations were affected, including Azure Functions, which broke CI jobs w...
Miasma npm worm hits Red Hat, new OpenSourceMalware research on 2026 trends, the Moika campaign
This week Paul and Jenn talk about:Miasma Campaign — Starting June 1st with 32 Red Hat @redhat-cloud-services packages (averaging 80,000 weekly downloads) compromised, the campaign expanded to over 80 packages and 286+ malici...
OSV false positives, Crowdstrike takedown of Glassworm infra, and MSFT nukes a researcher
This week Jenn and Paul covered:OSV false positives from AWS Inspector: AWS's automated malware detection pipeline submitted 157 false positive entries to osv.dev. The entries were merged before anyone caught the errors. When...
GitHub popped by malicious VS code extension, npm staged publishing debuts
This week Jenn and Paul cover:npm Staged Publishing: npm's new feature adds a human approval checkpoint before a package goes live. Real improvement, real caveats. We walk through what it does, where it falls short, and the q...
RubyGems bot attack, ShinyHunters ransom Canvas, and the latest on Mini Shai Hulud
Join OpenSourceMalware co-founders Jenn Gile and Paul McCarty for episode four!In this episode:RubyGems bot attack: Hundreds of bots pushed 500-plus packages to RubyGems, some carrying exploits, forcing the registry to...
Git hook persistence, Antrea compromise, Dirty Frag, cPanel exploitation, interpreted language malware
Join OpenSourceMalware co-founders Jenn Gile and Paul McCarty for episode three, covering the latest threat activity and a deep dive they've been promising since episode one.In this episode:DPRK Lazarus Group using git hoo...
Lovable and Vercel incidents, GitHub RCE, EDR vs. AI agents, Mini Shai Halud by Team PCP
Join OpenSourceMalware co-founders Jenn Gile and Paul McCarty as they cover a week that had defenders everywhere ready to call it on 2026.In this episode, we cover four topics:Lovable and Vercel incident response failures:...
Bitwarden CLI compromise, npm lifecycle scripts, OWASP cheat sheet, cross-ecosystem attacks
Welcome to the very first episode of The OpenSourceMalware Show! Join OpenSourceMalware co-founders Jenn Gile and Paul McCarty as they break down the latest news, threats, and best practices in the open-source ecosystem. In this ep...