BLOG
The OpenSourceMalware Show #7
Miasma npm worm targets Red Hat via trusted publishing abuse, OpenSourceMalware 2026 threat data, and the gray-area Moika campaign.
By cb482791-4ef1-4762-96ad-b0ca4bdd538e ·
The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.
In this episode we covered:
Miasma Campaign — Starting June 1st with 32 Red Hat @redhat-cloud-services packages (averaging 80,000 weekly downloads) compromised, the campaign expanded to over 80 packages and 286+ malicious versions within days. The worm is the first confirmed in-the-wild use of TeamPCP’s open-sourced MiniShai Hulud worm, though TeamPCP has not claimed credit. It is multi-ecosystem (npm, PyPI, RubyGems) and the Ruby variant appears to be LLM-translated, not part of the original open-sourced code. The initial Red Hat compromise came not through a GitHub Actions vulnerability but through abused gaps in npm trusted publishing. A live comment from Francois (VP of Security Research at BoostSecurity) corrected this in real time during the show.
The Shift from Human to Machine Attack Paths — Account takeover attacks have shifted away from social engineering as the primary foothold. The Axios compromise in early 2026 was likely the last major example of a social-engineering-based entry point. Threat actors now primarily target CI pipelines, automated builds, and developer tooling. Automation has also accelerated post-compromise activity: credential abuse now begins within seconds of a system being popped, rather than requiring manual follow-through.
OpenSourceMalware Data Trends (Jan to mid-May 2026) — Three trends from six months of OSM threat report data. First, npm remains the dominant ecosystem by volume but PyPI is growing at a comparable rate and the two frequently correlate, reflecting multi-ecosystem attack campaigns. Second, the vast majority of malicious packages have fewer than 10,000 weekly downloads (indicative of typosquatting and dependency confusion), but the share of high-download packages has grown over the period, with account takeovers representing 60 to 65% of new records in the week of May 11th. Third, malicious ClawHub skills have grown rapidly since January, with over 700 in the database by end of March. Nearly a fifth target marketing roles (SEO, Klaviyo, TikTok, YouTube), reflecting threat actors going after non-developer users of AI tools.
Moika Campaign — Over 260 verified threat reports tied to infrastructure at oob.moika.tech, with nearly 300 packages deployed. The campaign sits in a gray area: the account has a history consistent with bug bounty research (PoCs, packages without payloads, version numbering at 99.9 to float above legitimate packages), but the payloads on others are overtly credential-stealing and one researcher has attributed the campaign to a Russian nexus. This connects to a broader conversation about the volume of security-researcher-style packages in the ecosystem: between October 2024 and January 2025, between 25 and 41% of malicious packages entering OSV were attributable to bug bounty researchers. The episode also covers AI hallucination as an attack vector, using Events Channel (still live on npm with 168,000 downloads despite being reported) as an example of how LLM-hallucinated package names get weaponized.
Episode Resources
(blog) Miasma: Supply Chain Attack Targeting RedHat npm Packages
(blog) Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
(blog) The Software Supply Chain Malware Landscape: January - May 2026
(blog) 183 npm Packages Target Cloud and Finance via oob.moika.tech
[00:00:00] Jenn Gile: Hello. It is June 4th, and Paul and I are back. We have a diverse, interesting agenda for today. We’re gonna talk about what’s now being called the Miasma campaign, but started with Red Hat getting popped. We’re gonna talk about Moika, which has also been in the news. We’re gonna talk about some research we released. But before we get to that, Paul, what’s up?
[00:00:37] Paul McCarty: Yeah, man, it’s just a beautiful day here in Queensland, Australia. G’day, mate. The rain has finally bloody stopped, and the sun is out. And I have a guy here digging a trench for me. He’s doing it by hand. So this guy is making his money the old-fashioned way, which is good on him, 'cause I broke my f***ing toes. I don’t
[00:01:00] Jenn Gile: know if I told you, when I was in college, I did a road trip in South Australia, and for whatever reason, like, everybody we met were, like, tradies in Australia. Like, I met, like, a bricklayer, and I don’t know. Like, I don’t… It’s just not something that you tend to meet here in the US.
[00:01:14] Paul McCarty: I know. Yeah. We are a culture and a nation of tradies, and yet, at the same time, in a weird state, we also cannot get tradies to come to your house. Like, I’ve had multiple people say they were coming, give me quotes, and they just then don’t show up. True story. And when I talk to them, they’re like, “Yeah, you’re in the too hard bucket.” I’m like, “Well, for a nation of tradies, you sure don’t show up very often.” Boom.
[00:01:50] Jenn Gile: You know, we have the same thing here. If your job isn’t big enough, a lot of times people won’t call you back. I don’t know. They’re all often self-employed. Hey, shout-out to the other self-employed people out there. It’s pretty great most of the time, but sometimes it makes things hard to get organized. Anyway,
[00:02:00] Paul McCarty: let’s… I just wanna say one thing. The difference is Australians are polite, and so they won’t say no. They’ll do the whole quote in front of you, or they’ll do it all up, right? And then they just won’t get back to you, or ghost you a little bit later. That’s the difference.
Miasma Campaign: Red Hat and the npm Worm
[00:02:35] Jenn Gile: Fun. Okay, we’re gonna start with Miasma, and this kicked off June 1st, was that three days ago? That sounds right, with Red Hat getting compromised. 32 of their cloud services packages that cumulatively average 80,000 weekly downloads were compromised. It was done via a GitHub Actions vulnerability. We’ll get into that more later. But what I think is the most interesting part about this is where the malware came from. It is an npm worm. It is the first example we’ve seen in the wild of TeamPCP’s open sourced version of the MiniShai Hulu worm getting used. So there’s no indication at this point that it is, in fact, TeamPCP. And given they’re not claiming any kind of credit, probably not. It’s probably a copycat of someone who said, “Yoink. Thank you.” But this worm’s kinda interesting. It, like I said, came in through a GitHub Actions thing. We’ll talk about that. It also is multi-ecosystem, so we’ve got npm, PyPI, and surprise, RubyGems. And I don’t think their open source code included a Ruby variation. So I think we can make some fair assumptions that this is another example of threat actors likely using LLMs to make some modifications to malware so that it’s more ecosystem agnostic. They’re out there making sure everybody gets attention. So thank you for that.
[00:03:55] Paul McCarty: Yeah, indeed. I liked how Adnan Khan described this as, “Claude, go pack every single TTP into one giant TypeScript mess.” It’s like, it’s just pretty accurate. And if you look at, for example, I’m looking at the code right now for the info stealing part of this, right? What it’s stealing is basically what every other info stealer right now is stealing. And this is something I’m gonna zoom out real quick. We are just seeing so many info stealers popping up, like they’re everywhere. And we expected this, right? Because of LLMs and everything else and open source and everything else. But at the same time, now we have to deal with it, right? But just looking at this section, it’s like every info stealer right now is just grabbing everything, and they just keep adding these. So now they’re grabbing the vault from HashiCorp, you know, they’re just… Back in the day, Invisible Ferret was…
[00:04:52] Jenn Gile: I got a comment here. Our friend Francois says there was no vuln in the workflow. They audited all of them well before the attack. It was most likely an InfoStealer, but they abused some gaps in trusted publishing. That’s
[00:05:00] Jenn Gile: helpful.
[00:05:10] Paul McCarty: Yeah. Francois would know better than I, for sure. And just watching this, you know, Claude suggesting the same InfoStealer section every time, every bad guy that is writing malware right now is just seeing the same patterns again and again in these sections is funny. But anyhow, moving on.
[00:05:35] Jenn Gile: Well, not moving on yet because it didn’t stop at Red Hat, right? It is up to over 80 compromised packages. Our friends over at STEP published a blog yesterday about kind of the second phase of this. They compromised 57 packages. They said it was across 286 at least malicious versions. So probably not the last that we’ll see of this. I’m not sure if this is the same threat actor as the Red Hat one. They’re awfully close together, so potentially. What do you think, Paul?
[00:06:00] Paul McCarty: Yeah, I mean, Rami-Mac and others are, as you and I briefly talked about earlier, saying that they’re probably the same threat actor. So there’s that. And again, I trust Rami. The problem is that when TeamPCP open sourced this, suddenly they created a world, a universe where people could be using their tradecraft and evolving their tradecraft, and TeamPCP could not claim responsibility for it, right? But that just seems like such an odd thing for TeamPCP to do 'cause they’re just such clout chasers, right? They’re just constantly talking. So in my head, there’s pretty good possibility that this is some part of the actual TeamPCP crew doing this. They just haven’t claimed it yet for whatever reason. Maybe it’s a part of the crew that doesn’t like Twitter. I don’t know.
[00:07:00] Jenn Gile: Maybe they’ve been listening to us saying, “Hey, stop with the self-promotion.” Stop yapping, right?
The shift from human to machine attack paths
[00:07:25] Jenn Gile: Okay, segueing here. I had a conversation with somebody this morning that’s very relevant to this attack. They said, you know, “Aren’t all these account takeovers coming from social engineering campaigns?” And I said, “You know, that was true to some extent up until we’ll say the Axios attack in early April, late March timeframe, is probably the last time I remember a social engineering foothold for one of these.” And what we’re now seeing is it’s much more likely to be something on the pipeline. So they’ve moved from the human path being the weak link to the machine path being the weak link, and I think there’s a lot of consequences to that change. There’s a lot of reasons I’m sure they’re doing it. As people understand better what’s going on and perhaps it gets a little bit harder to compromise people through social engineering, you start to look for alternatives, and certainly we know there are big gaps in security for pipelines. And yeah, Paul, what do you… I know you’ve looked into this a fair bit about the machine path. What would you share with people?
[00:08:30] Paul McCarty: Yeah. I mean, I think that they’re… It’s true. This is not using social engineering in any way. I mean, I think we’re past that. I think those days of classic contagious-interview-style, fake-recruiter social engineering are behind us. I think they’ll be used with these big spear kind of things like what happened with Jason and Axios. But no, this is affecting, this is attacking us through CI pipelines, automatic builds. So these are things that we don’t have necessarily the amount of visibility on that we should. But also through
[00:09:00] Paul McCarty: attacks on developer tooling, right? Like the reality is that this is affecting the supply chain, and the supply chain is a chain. And part of that chain is what developers are using. And I wrote this up years ago when I wrote up the DevSecOps playbook. I called out specifically, years ago, that developers and the tools they’re using were part of the software supply chain. So yeah, affecting the AI tools, Claude and other tools that are running on developers’ laptops, and in some cases in CI pipelines. Also the VS Code and the IDEs that people are using. It’s moved on to a more automated, scalable attack. And that era of having to social engineer people is mostly behind us, except for those really big whales.
[00:09:55] Jenn Gile: Yeah. I mean, I think social engineering will always be an attack vector. I think it’s more of a wide net thing. And you’re right, it’ll be more targeted. What we saw with Axios was a very sophisticated operation. They were not casting a wide net with an email and trying to get everyone. They targeted a single person very specifically. But yeah, we’ll see how this continues to evolve, and hopefully start to see some changes made in pipelines.
[00:10:25] Paul McCarty: Yeah, agreed. And I think it’s worth mentioning that this worm and the TTPs this tradecraft is using is evolving really, really quickly. And automating many of these steps that used to require the threat actor to wait to get the credentials back, sort through them, and then do the next stage. Well, now that’s just automated. As soon as something gets popped, what we’re seeing is within seconds or split seconds, those credentials are used to go out and find additional stuff, drop things into GitHub Actions, and away they go. So between the evolution and the iteration and the automation, it’s just scary. I’m at the point now, true story, I just don’t wanna use GitHub. Straight up, I just don’t wanna use GitHub. Full stop.
[00:11:05] Jenn Gile: Yeah. I mean, especially after the response that we saw when they were compromised, what, a couple weeks ago by the NX console VS Code extension. We didn’t get a very good
[00:11:00] Jenn Gile: explanation. It’s been pretty quiet. But also, unfortunately, that’s the response that you tend to see from bigger companies. Oh, we’ve got a comment here. Ex-GitHub employee: I agree, and it breaks my heart. Yeah. Yeah. It’s a bummer.
[00:11:50] Paul McCarty: Me too. It… I love GitHub. For a lot of people, GitHub was pivotal in their career, this idea, you know, like… And even though it’s owned by Microsoft and I do not have any love for Microsoft, let me be very clear, I’ve always had this special place in my heart for GitHub and the people that work there, and I’m just not gonna use it anymore. Full stop. Like, I’m done.
[00:12:10] Jenn Gile: Taking a stand. Time to start migrating.
OpenSourceMalware data trends: packages, popularity, and malicious skills
[00:12:15] Jenn Gile: Well, let’s talk about the next one on our list. What is it? We talked about trends, now we’re gonna talk about what our actual data, so I guess it’s still trends. We’re gonna talk about trends that I’ve found in looking at open source malware data. So I’m gonna go ahead and drop this blog in the comments.
[00:12:25] Paul McCarty: This is so sick, by the way. I just wanna call this out. You did a great job with this.
[00:12:30] Jenn Gile: Thank you. So the backstory here is, like, maybe a month ago I was like, “Paul, get me a CSV with all of these things.” He was like, “Why do you want that?” It’s gonna be great.
[00:12:55] Paul McCarty: And, and to be clear, I didn’t ask why, I was just like, “Yeah, sure, go to town.” Like she was perking a list of old product updates.
[00:13:00] Jenn Gile: Yeah, yeah. I had, because we’re very responsible with our data, I had Paul export a whole bunch of data from OpenSourceMalware, starting in January through mid-May. And I wanted to know, six months roughly of data, what can that tell us? And it was very… About specifically threat reports. Yes, threat reports. Specifically threat reports. I should be really clear about what I was looking at. And three trends were pretty obvious to me as I started noodling around in there. The first is about packages. So I looked across all of the package ecosystems that we track, both for volume as well as velocity of new reports. And no surprise, npm continues to be where the lion’s share of
[00:14:00] Jenn Gile: malicious packages are. But what was very interesting, and kinda calls back to an earlier conversation we had here, is PyPI is growing at roughly the same rate throughout this period. And we see them kind of weave back and forth, where one week PyPI will be higher and one week npm will be higher. And I looked a little deeper in that data, and what I found is there’s a couple of edge cases where the reason there’s more PyPI is because people were looking more diligently at PyPI. But in most of the cases, there’s a correlation between when an npm package and a PyPI package published, and it’s that exact circumstance of the threat actors being multi-ecosystem.
[00:14:55] Jenn Gile: And so I think based on this data, we can expect to see an increase continuing to grow in PyPI. That’s what that tells me is most people are very aware of the dangers in npm. I don’t hear a lot of awareness about PyPI.
[00:15:10] Paul McCarty: Yeah, I mean, I think I’ve been saying on stage and in other places in my writing for ages that while it’s obvious that the total volume is much lower in PyPI, the percentage of growth and the activity is at least the same as npm on a percentage basis or greater. I think people think that PyPI is relatively safe relative to npm, but there’s a bunch of things that they don’t do well in the PyPI world either. I really wish, for example, that they verified the metadata inside PyPI about the author, right? Those are free form fields. You can stick anything in there you want to, but I’m going off subject, sorry.
[00:15:55] Jenn Gile: No, that’s on subject, because I think the point is if you use
[00:16:00] Jenn Gile: Python, make sure you’re applying the same practices to hardening what you’re taking from Python as you would for JavaScript, right?
[00:16:05] Paul McCarty: Yeah, and like all these little ways for people to automatically run files in the node space and those path files in Python, which threat actors were using like three or four weeks ago. There’s a lot of ways for bad guys to attack us that aren’t necessarily well known, right? And the other thing too is that Python is gonna be making some changes to their tokens and personal tokens, and that’s good. I think they’re much more responsive than the npm team certainly is, so good on them. But I’m not surprised to see your data.
[00:16:55] Jenn Gile: Okay, the second thing I wanted to look at was popularity of packages
[00:17:00] Jenn Gile: because there’s been a tremendous amount of attention paid to account takeovers that have compromised a legitimate package, and that’s fair because those are often high-download-popularity projects. And so I took all the data from that time period, again looking specifically at npm and PyPI, and broke it down based on average number of weekly downloads the week that it was reported. And there’s an interesting trend. First off, no surprise to me, no surprise to Paul, the vast majority of malware has less than 10,000 downloads a week. And that is indicative of those packages being more likely, not definitely, but more likely to be dependency confusion or typosquat packages that are very specifically targeting a
[00:18:00] Jenn Gile: group of people rather than those big Axios takeovers. But what we’re seeing over time, if you follow the graph and pop into the blog that I pasted there, and you can play with it to your heart’s content, is you’re seeing over the last month for sure, more high-download packages being represented in the data. So threat actors are successfully getting access to more potential victims. The second part of that analysis was to specifically look at account takeovers, because it’s like an imperfect but okay correlation where you say, “Well, if it’s high download, then it’s probably an account takeover.” But not always. So I also looked at what we tagged as account takeovers. And the line is similar, it’s still lower, with a spike in March around the
[00:19:00] Jenn Gile: time that Team PCP really started getting active, and then a secondary spike when MiniShaiHulud took off. And the number that surprised me, and I really wanna look at the data again in maybe like a month or so, is around May 11th, about 60, 65% of the records that were added during that week to OpenSourceMalware were account takeovers, and that is a bananas number of records. So it’s not that account takeovers are the whole story, but they’re definitely a story.
[00:19:10] Paul McCarty: Yeah. I mean, I think, no surprise again with TeamPCP and other attacks like Axios targeting these high-volume popular maintainers. I also think that while the data shows that the number of those, the percentage of those has gone up inside of our data set, that
[00:20:00] Paul McCarty: is the group that many of these changes that are happening inside the npm ecosystem and other places are most positively going to affect. Cool-down periods, as much as I’m a realist about cool-down periods, are absolutely a great precaution and control for these style of attacks. Because they do get found quickly. But as we make these changes to the ecosystem, we’ll see those, the percentage of those go down. And I think it’s important. What we’re already starting to see is we’re starting to see these high-volume, high-impact packages are out there for a relatively short period. And because they have a lot of weekly downloads, they rack up a large number in that window. But then you see also some of these other popular ones, like Events Channel is a really good example. You see these popular typosquatting or dependency confusion attacks that are out there much longer.
[00:21:00] Paul McCarty: So if you do the math, if you look at that 18 minutes big versus less popular but out there for weeks, like Events Channel, I let Microsoft know about this a week and a half ago, right? And it’s still up.
[00:21:05] Jenn Gile: Along with a lot of other packages. Yeah, I actually pulled this one up this morning when I was talking with someone and yep, I just clicked it again. Events Channel is still live on npm. This is a confirmed typosquatted package that’s targeting Node.js users, and it has a total of 168,000 downloads. That’s not nothing.
[00:21:55] Paul McCarty: Sounds about right.
[00:22:00] Jenn Gile: So to your point, those point-in-time big spike account takeovers are gonna get a lot of people in a short amount of time. And they’re gonna get the people who don’t have cool-down periods in place, or who don’t have some kind of dependency pinning or dependency management process in place. These more under-the-radar ones stay up for so long because they don’t have a package maintainer screaming, “Hey, my stuff got taken over. Please fix it.” And so yeah, it’s really unfortunate that this package is still live. It’s still getting downloaded. We reported it. We’ve posted about it on social media, and it’s still live. Where was I going with that rant? I don’t know.
[00:22:50] Paul McCarty: That’s okay. Well, and then there’s a third state here. You ready for that? We, Jenn and I, haven’t even talked about this yet, so I’m going off topic again. But there’s a third state here, where we’re now starting
[00:23:00] Paul McCarty: to see GitHub accounts and npm accounts that haven’t been used in a long time, that have now been compromised, and they’re using them like they were a born-malicious package. So they basically dump a bunch of malicious repos. They start publishing packages under this name. In one case, they’re using the guy’s actual domain that he has spun up. They’re using that domain for the exfil now, so they’ve just taken over all of his infrastructure. We’ll talk about this in more detail next week.
[00:23:40] Jenn Gile: I mean, it’s a heck of a lot easier to steal that than it is to artificially age something. And still a lot of people are surprised that you can inflate downloads in GitHub, but…
[00:23:55] Paul McCarty: Yeah. As a corollary to that, I also noticed that the price that bad guys were charging for aged GitHub accounts on the dark web has gone up pretty dramatically. It’s gone up by about 8x or 10x now. They used to be able to buy these things for like 12, 15 bucks an account.
[00:24:00] Paul McCarty: And now they’re well over $100 each, so there you go.
[00:24:15] Jenn Gile: Lovely. Okay, the last piece of data in the analysis that I shared in the comments is specifically about malicious ClawHub skills. We had a feeling when this came out in January that this would be a threat actor playground, and Paul, you were not wrong. You found, what was it, 386 malicious skills within like two days, and then by the end of March we had over 700 in the database. And so I took all of those skills and I cheated a little bit. I looked at the name of the skill
[00:25:00] Jenn Gile: because that’s what threat actors will do, is they’ll name it the thing that they want you to think that it is. So I don’t have to go look at the skill to know what they’re trying to copy. And I broke it down into categories based on what kind of technology were they targeting in that. And there’s definitely some “here’s my shocked face, I’m not surprised” categories. Like, they went after crypto? Really? Crypto and finance was number one. Certainly there were some that went after developers, but the big surprise is that almost a fifth of the skills were targeting somebody in a marketing job. And we know that because they have titles that reference SEO, that reference things about YouTube and social media, Klaviyo, which is a popular platform for customer marketing. There’s a ton of stuff that is very obvious.
[00:26:00] Paul McCarty: A bunch of them were targeting TikTok.
[00:26:02] Jenn Gile: TikTok, you’re right. So I think this is part of a conversation that we’re all a little ostrich, head in the sand, about. We know developers are a target for malware. We know developers are a target for threat actors, but we also know everybody is being asked to use AI, and most of those people don’t fall under the umbrella of application security, right? My code that I write as a marketer or a salesperson or finance is not getting scanned in the same way that a developer’s code is getting scanned. So I think we’ll see more of this.
[00:26:40] Paul McCarty: Yeah, I totally agree. I think bad guys realize that LLMs and agentic
[00:27:00] Paul McCarty: development tools allow people that are not natively software engineers to go and build tools and products and data sets and data. And it makes a lot of sense to be using the distribution of the AI agents, and the skills and everything that goes along with it, to attack people that are writing code or building products that aren’t software engineers, that have other primary roles, whether it’s marketing or what have you. With the democratization of agentic software development comes a new way to attack people that are not natively software engineers.
[00:27:20] Jenn Gile: Yeah. Going back to what we said earlier about the human path versus the machine path, in some ways that’s what’s happening here. Typically, marketers were getting targeted more by phishing campaigns, and I’m sure that will continue, but this is a way to target marketers without relying on the same
[00:28:00] Jenn Gile: type of social engineering. Anyway, we are gonna take a nice chunk of time now and talk about another campaign that’s been in the news.
Moika campaign: bug bounty gray areas and AI slop malware
[00:28:00] Jenn Gile: And the reason we’re gonna take some extra time here is not so much that the malware itself is super interesting, but there’s a lot of history. You may have heard it referenced. We’re calling it the Moika campaign, and the reason that we’re calling it Moika is because the infrastructure behind it has oob.moika.tech as a part of the infrastructure. They’re C2. To date there are over 260 verified threat reports on this campaign, and there’s not a lot of agreement in the community about what’s going on with it. So I’ll give the TLDR, and then Paul, I know you have a lot
[00:29:00] Jenn Gile: to say about this. The TLDR is the account associated with this campaign has a history of legitimate activity as a bug-bounty-type thing. Where it is today, publishing this volume of malware, and some of these have some decent download stats where it’s undoubtedly catching people. So I’ll drop a couple links, and Paul, why don’t you wax poetic about Moika?
[00:29:00] Paul McCarty: Yeah. Thank you for the opportunity. We are gonna go long today because I think this is important. We’ve had a long-term issue with researchers, security researchers, and especially bug bounty researchers, building malicious npm packages and now doing stuff in other ecosystems too as well. And this goes all the way back even before
[00:30:00] Paul McCarty: Alex and Justin dropped the dependency confusion research in 2024. People have been doing this to collect bounties for a while. So we have a long-term behavior set of researchers creating malicious packages. Now, there’s kind of this accepted need for this to happen because bug bounty platforms and programs wanna know if they’re susceptible to dependency confusion and other software supply chain attacks, right? So there’s real genuine validity to security researchers making these things. But we kind of expect that generally they follow a set of guidelines here, right? Which is that they do no harm. It’s like the Hippocratic oath. They typically pull the public IP address and maybe a hostname and maybe a username and maybe a couple other really minor things, but what they don’t wanna do is exfil a password or important data, because then they cross an ethical line.
[00:31:00] Paul McCarty: So we have all these people doing this research, and in 2024, from October through December and into January 2025, I validated the percentage of packages that went into OSV at the time, seeing what percentage I could attribute to a bug bounty researcher. And I saw that the average was somewhere between 25 and 41% across those three months. So let’s just say that in another way. Somewhere between 25 and 40-plus percent of the malicious packages going through OSV in late 2024 were attributable either directly or indirectly to these researchers. So it’s a large percentage of what comes into the ecosystem, and then researchers like me and Charlie and everybody else have to deal with it. We understand these actors.
[00:32:00] Paul McCarty: So the next thing we wanna talk about is researchers that have been doing this for a while, and one of them is Darshan. Darshan’s been around, JPD is their call sign, and I know Francois is probably giggling to himself right now. JPD has been doing this for ages. I’ve been tracking him since 2024 at least. He’s a bug bounty researcher, dependency confusion and to a lesser extent typosquats are what he does, and it must be successful because he’s been doing it for ages. He always attributes in each one of his packages his initials, the email address, so you can basically almost 100% of the time attribute a JPD Darshan package back to him.
[00:32:40] Paul McCarty: Now, Darshan does cross the line sometimes. I’ve seen him do some things that cross that ethical researcher line. But he’s a known…
[00:32:45] Jenn Gile: Well, and he got called out for that, what, maybe in January or February. A lot of people in the community… I’ve called him out… yeah, not just called out, but a lot of people accused him of malintent.
[00:33:00] Paul McCarty: Yeah, exactly. 10-4. Now you can find him online, he’s on Twitter, he’s everywhere else, right? So Coy comes along in 2025 and attributes APT-level status to old mate Darshan, which I’m sure at some level Darshan was like, “Oh, look at me, I’m an APT,” but at the same time, “Oh shit, now I’ve got a bunch of people talking about me.” And me and a bunch of my peers inside the community are all kind of just like, “Oh God, this is not an APT.” What was it? Hidden Raven or Phantom Raven, whatever it was, right? Phantom Raven, I think. Anyhow.
[00:33:43] Jenn Gile: Yeah.
[00:33:43] Paul McCarty: So here we are. We have this history of all this kind of stuff happening, and now Moika comes along.
[00:34:00] Paul McCarty: And Moika has deployed almost 300 packages, and uses a lot of the kind of signals that you see in typical bug bounty. They use PoCs, security research. They actually called, and Jenn pointed out one of them specifically said bug bounty. They’ve published packages where they don’t actually have a malicious payload. They also number their dependency confusion packages using 99.9, which is the common way, because they’re trying to make their version the highest version. And there’s a bunch of other things that they do that all kind of makes the signal look like this is bug bounty or security researcher. But then you look at the payloads and you’re like, some of these payloads are just overtly malicious. They’re just ganking credentials. And one of the other researchers has attributed them to a Russian nexus. Now that doesn’t mean that there aren’t bug bounty researchers in Russia, but these packages don’t look like researcher
[00:35:00] Paul McCarty: packages to me, or at least not like the ones that I’ve seen.
[00:35:35] Paul McCarty: So it’s a weird thing. There’s not a lot of high impact here, but I think I wanted to talk about it because it does connect to this legitimate or semi-legitimate gray area of these bug bounty packages that we’ve been dealing with for years. We call them malicious inside of our ecosystems because you don’t wanna install one of those, right? Like, just because it’s targeting somebody else specifically. Now here’s the thing with Moika, Moika’s targeting very specific npm namespaces, so they’re like kind of systematically going through, targeting individual organizations. That again looks like bug bounty, but in this case the payloads don’t align to that kind of outcome. So I don’t know. It’s a weird one, and I wanted to talk about it as really a greater observation about the fact that we have a lot of
[00:36:00] Paul McCarty: volume of these malicious packages inside of our ecosystem that are created by people that are ostensibly researchers, or really are, and that’s part of what we have to spend time identifying and culling out.
[00:36:45] Paul McCarty: And is this a Russian threat actor trying to pretend to be a researcher? I don’t know. Just, it feels weird. And I’m seeing more of these weird ones as people get access to AI and LLMs and can generate more and more payloads.
[00:37:05] Jenn Gile: That was literally gonna be my question, because there’s been a lot of talk in the community about AI slop bug bounty stuff, right? Usually it’s oriented around CVE-type things. We’ve seen lots of programs say that a process is gonna be leveraged more based on the credibility of the person. I was reading HackerOne is gonna change their process, where it’s gonna be leveraged more based on the credibility of the person. If you’re a known researcher. Yeah, it’s a good change. And frankly, in response to what happened with Microsoft a week or two weeks ago burning a researcher, but I digress. We haven’t talked a lot about AI slop malware. What do you think is gonna happen here? There’s certainly the threat actors who are using AI to rapidly iterate, but what else are you seeing?
[00:37:40] Paul McCarty: Yeah, I mean, this AI slop thing, just to kind of define that quickly for our audience, is where basically an LLM hallucinates that a package exists. Let’s just say Events Channel. Events Channel shares a name with an internal process, but there’s also a 13-year-old package called Event Channel, which nobody uses. But anyhow, so an LLM at some point hallucinates that a package name exists and then suggests it to a user, and they include it in their package manifest or what have you. And a lot of times this is more behind the scenes. It’s just doing it, nobody ever looks at it and you don’t realize, right?
[00:38:00] Jenn Gile: And if
[00:38:00] Paul McCarty: I could
[00:38:02] Jenn Gile: interrupt… But then a bad… When I was at Encore… Right… we did some research on this last year, and it’s a shockingly high number of packages are hallucinating. Like, hallucinating.
[00:38:15] Paul McCarty: Yeah, I mean, the platforms have gotten better at it, but I think it’s kind of fallen to these kind of niche parts of the ecosystem where it’s much harder to attack. One of the ways that I see Events Channel being picked up is in MCP servers. There’s a bunch of DIY MCP servers that you can find if you just search on Google that are calling the Events Channel package. Why and how did it find that kind of niche? I don’t know. But this is where it’s happening. It’s all over the place. Bad guys then go and create a package with that name, and suddenly something that was a hallucination on the agent’s part is now an actual genuine malicious attack inside of your ecosystem. And it happens much more frequently than people think. And in this case, Microsoft hasn’t taken this thing off of the registry. It continues to be a fairly effective typosquat.
[00:39:00] Paul McCarty: So…
[00:39:30] Jenn Gile: Yeah. It’s the world we live in right now. Okay, we took our extra time. Did you get it all out of your system?
[00:39:35] Paul McCarty: Well, not really, but that’s okay. I got enough of it out that I feel good. I got a chance to vent about this weird bug bounty researcher fakeness, anyhow. Thank you, everyone.
[00:39:47] Jenn Gile: Well, there’ll be enough in the tank for next time, I’m sure.
[00:39:52] Paul McCarty: Right. We already are queuing up things to talk about next week too, so we got a full one.
[00:39:58] Jenn Gile: Yeah. Well, as always, if there’s stuff you wanna learn about, DM us, comment in our videos. I keep an eye on all of that. We actually had somebody, side note, reach out to us on I think last week’s video and say that they thought they had been hit by PollenWriter. So if you’re listening, DM us on one of our socials. We’d love to talk about it. But yeah, we’ll be here.
[00:40:00] Paul McCarty: Yeah, I still haven’t pushed the new blog about the latest .zip thing that PollenWriter’s doing, which is really brutally effective, so I’ll get that out there. Just been busy doing actual stuff.
[00:40:35] Jenn Gile: Well, that is stuff, but you have products to develop. Right on. Have a great one, everyone.
[00:40:45] Paul McCarty: Yeah. Thanks everybody. Appreciate you listening. Cheers.
[00:40:50] Jenn Gile: Bye.