BLOG

The OpenSourceMalware Show #14

Hugging Face breach claims, AgentBaiting malware, RubyGems leaks, and PolinRider infrastructure overlap

By cb482791-4ef1-4762-96ad-b0ca4bdd538e ·

The OpenSourceMalware Show #14

The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.

This week we talked about:

  • Hugging Face breach and OpenAI's rogue model claim — Hugging Face disclosed a breach with thin details; OpenAI followed up claiming one of its models caused it during an internal security test, escaping its sandbox. The security community is skeptical about OpenAI's role in this incident.

  • AgentBaiting: 6,000+ malicious GitHub repos target AI agents — Island's research found over 800 repos posing as AI skills or MCP servers, part of a wave that peaked in April. The bigger concern is malware hidden in natural-language instructions rather than code.

  • RubyGems GemStuffer copycat campaign — 2,539 new RubyGems threat reports resembling the GemStuffer campaign that used gem publishing as a channel to hide exfiltrated data.

  • RubyGems was leaking user API keys for years — A caching flaw exposed other users' API credentials under certain conditions. RubyGems fixed it fast and is notifying affected users.

  • CrashStealer: a macOS infostealer with multiple tracks — Jamf published research on this novel C/C++ infostealer impersonating Apple's crash reporter. Paul found the threat actor also running a RAT and other malware tracks in parallel.

  • Info stealers 101 — A quick primer on what characterizes an infostealer (what it targets, how it exfiltrates) and how our technology traces backward from the exfil point.

  • ChainVeil and ViteVenom are PolinRider — Jenn's research connecting Checkmarx's ChainVeil/ViteVenom npm campaign to DPRK's PolinRider via five byte-for-byte identical IOCs (wallets and XOR keys).

Episode Resources

[00:00:00] Jenn Gile: Okay. Hello. It is Thursday, July 23rd. Um, Paul, you're down in Sydney today. How are things in Sydney?

[00:00:10] Paul McCarty: Cold and blustery. Uh, but yeah, I think the temperature right now is nine Celsius, I think. Um, I'll tell you here. Uno momento. It is seven. I'm sorry, even colder. Seven. So yeah, I was wearing my, yeah, I was wearing my puffer.

[00:00:29] Jenn Gile: Well, up in the Seattle area, we are in, like, the heat of summer. It's been miserable, um, but it got cooler today, so hopefully, I don't know. You and I have another week before we head to Las Vegas, and, uh, pro tip, this year I'm packing a humidifier because it is so dry, and by the end of the week, like, I can't wear contacts.

[00:00:50] Jenn Gile: I'm dried out. So this year, the humidifier's coming with me

[00:00:54] Paul McCarty: Yeah, going from Seattle to, I mean, like you and I were saying this earlier, Seattle or the Gold Coast where I am, both

[00:00:59] Jenn Gile: Nice and humid

[00:01:01] Paul McCarty: right? I think the difference is, I was saying this earlier, is that because I lived in Utah for so long, my body, even though it's been, I've been away from there, kind of is used to it.

[00:01:08] Paul McCarty: So I get, my lips get... Yeah, it gets, my lips get cracked and all that, but then I get used to it, so

[00:01:13] Paul McCarty: anyhow.

[00:01:14] Jenn Gile: yeah. All right. We

[00:01:15] Paul McCarty: Our listeners are like super stoked about this.

Hugging Face hacked by OpenAI?

[00:01:19] Jenn Gile: We've got quite the list of things to talk about today. Um, in no particular order, the first thing on my list is the disclosure from Hugging Face that came through, I don't know, three, four days ago. Uh, they said that, uh, and I'll quote here, "A dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers."

[00:01:43] Jenn Gile: And, uh, I took a look at their, um, disclosure, a lot of other people in the community did. It was a lot of like, "We can't really tell what you're saying happened here." Um, a lot of people said it was very obviously written by AI, which I cons- concur, which I, I will say is, you know, not always the greatest thing in your, your IR reports.

[00:02:04] Jenn Gile: But then, um, what, yesterday, uh, we saw a follow-up. OpenAI came out and claimed that one of its models, uh, did the exploit, that it broke itself out and whoops, sorry, we hacked Hugging Face. Um, they said it was an internal cybersecurity test that went awry. Uh, they claimed that it had escaped a isolated testing environment, reached into Hugging Face's system from there.

[00:02:33] Jenn Gile: Um, we're seeing two reactions to this news. One reaction is, uh, kinda just the news being, uh, put out there as true, that, "Oh my gosh, this thing happened. OpenAI did this thing." And then the other side, uh, which is mostly hanging out in the cybersecurity community, cybersecurity community, that's a lot of words, is, uh, people calling BS on this claim.

[00:03:01] Jenn Gile: And there's various reasons for why people are calling BS on the claim, but ultimately it kind of comes down to a lot of the community thinks that it's a marketing stunt and that this did not really happen or didn't happen in the way that maybe they're saying it did. They're not providing very much information.

[00:03:19] Jenn Gile: So Paul, uh, you've been looking into it. What's your hot take?

[00:03:25] Paul McCarty: Oh, man. Well, I'm definitely in that other camp, the, the skeptical camp. I wouldn't say that I'm like, I don't think, you know, I think it's, I think there's some nuance to my position in the sense that... All right, so I, I would say the first group is the singularity group, right? Like, "Oh my God, this is, this is evidence that AI is AGI," and all this other bull pucky.

[00:03:46] Paul McCarty: And I think the other group that I fall squarely in is the much more skeptical group. Um, so the details are light, which is always concerning, right? And you see this kind of theme coming out of the, the AI labs where they like to make these big f- splashy things they call incident response, you know, p- publications or whatever, but they really are lacking.

[00:04:11] Paul McCarty: They weren't written by people that do IR or anything, right? So, um, short story long, uh, just the details are missing. The idea that, uh, like a lot of people in the, in the skeptical side think like, "Oh, how could OpenAI's, you know, security be so lax, la-" sorry, "be so poor that, that, you know, it could find this way, the hole out from the isolation and, and out to the internet," blah, blah, blah.

[00:04:36] Paul McCarty: I don't see that as being that, you know, that's not a deal breaker for me. But what is a deal breaker for me is that they just haven't talked about, you know, what happened, and so just my immediate flags go up. Um, yeah, I mean, that's, that's basically it.

[00:04:53] Jenn Gile: Yeah, this is a suspicious by default community, so, uh, a report with thin information is not necessarily, um, encouraging. And we've been seeing these, um, frontier model companies doing things that certainly the pattern is, "Oh my gosh, look how dangerous this thing is." And, um, it's, it's an interesting marketing strategy.

[00:05:20] Jenn Gile: Okay, segue.

[00:05:21] Paul McCarty: just, I just want, I wanna say one more, uh, just, sorry, I wanna say one more thing that I forgot to say in my first little blurb. I- it's unfortunate, 'cause you're right. I think a lot of people are, are listening to OpenAI here and thinking, "Oh, this is just you trying to, you know, drum up something after the whole Mythos cra-," you know, this whole cultural shifting thing about Mythos, right?

[00:05:37] Paul McCarty: You have people that have no idea asking me, "What do you think about Mythos? Is it," you know. But, um, but here's the thing is OpenAI's latest models are actually very capable and relatively inexpensive and crushing it. And so it's unfortunate that if this really is some sort of marketing ploy, and it feels like at some level, some end percentage of this is really just, you know, marketing fluff around something that might or might not have happened.

[00:05:59] Paul McCarty: But, you know, it's unfortunate they're, they're doing that instead of just, like, letting their models speak for themselves, because I and a lot of other people, because of the Anthropic shizzle show, have moved over to OpenAI and other models, and they're very capable. So m- maybe try to win on the merits of your models rather than making up this contrived mission impossible bullpucky scenario, all right?

[00:06:23] Paul McCarty: Sorry, anyhow.

[00:06:24] Jenn Gile: We'll have to keep our eye on it. Okay.

[00:06:26] Paul McCarty: All right.

GitHub AgentBaiting and RubyGems GemStuffer Copycats

[00:06:27] Jenn Gile: We added, I just did the mental math, almost or maybe over 10,000 new threat reports in the last few days outside of our normal, uh, ingestion pipelines. And those two, uh, that, that huge boom in new records came from two places specifically. And so the first one is in GitHub and the second one is in RubyGems, and they're two very different scenarios, totally unrelated, but both uniquely interesting to talk about.

[00:07:01] Jenn Gile: So the first one, the GitHub one, uh, more than 7,000 malicious repositories, GitHub repositories were, um, disclosed by a company called Island in a campaign they're calling Agent Baiting, where they said, uh, at least 800, maybe more of those repositories are posing as AI skills or MCP servers, and this is a wave that peaked back in April.

[00:07:27] Jenn Gile: Um, so we have, of course, added those repositories to, uh, our threat database. You can pull them, you can see them today. I think they're under the Agent Baiting hashtag. However, um, I think what's interesting here is less about, "Oh, these repos are scary, you know, block them," and more the trend that we're seeing and that worries us and should worry the industry about where malware is heading and how threat actors are going to be able to take advantage of natural language

[00:08:02] Paul McCarty: Yeah. Um, a great segue. I mean, the, the concern here, basically the, the intent here, and there's just a, there's a lot of repositories in this campaign, right? And so the idea here was those, those repositories were created by bad guys, threat actors, non at- non-attributed bad guys, to basically then be pulled in as dependencies or, um, subject matter, uh, publications.

[00:08:30] Paul McCarty: You know, so basically when the, the AI was looking for, you know, hey, what's the strongest, you know, AI model for dental hygiene or I don't know, whatever, you know. Like, it goes out and finds these things, um, uh, which is a very, very... I mean, it's a common thing we're seeing. Like, so the, across the board in NPM and in VS Code and all these ecosystems, we're seeing bad guys really kind of focusing on AI MCP and, and, and AI aligned kind of, um, you know, malicious stuff.

[00:09:02] Paul McCarty: Um, and there's like a... And I'm saying stuff because there's just so much of it across the board, but they're targeting, um, those areas because what they wanna do is they wanna get to that natural langry, sorry, that natural language boundary where, you know, you can get it into, um, an agent and have it do the bad things.

[00:09:20] Paul McCarty: So for, for the vast majority of these things, they pretend to be, um, a, a subject matter expert publication about a thing. They get pulled in and they've got instructions, natural language instructions inside of them that does the bad thing, pulls payloads and goes from there. Um, yeah, and

[00:09:37] Jenn Gile: and the point here is that's harder behavior to detect because many of the tools that are out there are designed around detecting the code that does the bad thing, not the natural language instructions to do a bad thing

[00:09:54] Paul McCarty: Yeah. And I'm also, I'm concerned, like, first I'm concerned on two fronts. First, uh, because this is just a whole new thing and it's just, we've never seen anything like it, and there's not really a lot of ways to protect ourselves from this. And it's, it's concerning for me both personally and, and as well as, you know, kind of professionally.

[00:10:10] Paul McCarty: So that's one thing. But the other thing is that I think what'll happen now is that the whole industry, you know how the cyber industry is very, you know, thematic, will be like, "Oh, we need to address this." And we'll just, all the effort and budget dollars will all go towards that, which I'm not, uh, you know, I'm, I'm expecting it, but I'm also worried that then we're gonna, like, just drop the ball, because historically this has often happened.

[00:10:32] Paul McCarty: We drop the ball in those other areas that have been successful for us, right? Those places where we still need to do the things like make sure the bad malicious packages aren't being, um, ingested into your NPM, your JavaScript, or your Python applications

[00:10:44] Jenn Gile: a great point. I mean, we see that, uh, on repeat in the tech industry, whether it's cybersecurity or not. You know, we, you and I both lived through the on-prem to cloud, on-prem is dead kinda, uh, you know, phase. Um, there have certainly been other phases like that where it's, you know, "Oh, agents are here and no one's ever gonna write code again."

[00:11:08] Jenn Gile: The truth is always somewhere in the middle. Uh, there will continue to be your standard malicious packages that will continue to get harder to detect, um, through the means that we've been talking about on this show, uh, whether that be, you know, clustering or hiding things in dependencies, but they will continue to be code.

[00:11:26] Jenn Gile: And then there will be a set that will be this novel approach of hijacking an agent through, um, natural language. So yeah, the truth is somewhere in the middle. We're gonna need both. Uh, beware the hype because it's coming.

[00:11:42] Paul McCarty: And beware the hype.

[00:11:44] Jenn Gile: Okay. The second burst

[00:11:47] Paul McCarty: so many things to say, but I'm not going to.

[00:11:49] Jenn Gile: Yeah. Moving on. Uh, you added 2,539 new RubyGems threat reports to the database this week. And when you messaged me, I was like, "Are you sure? Ruby? Really? What's going on over there?" Um, and again, this is another, like, something unique is happening. Um, these packages have indicators that suggest that they're similar to the Gem Stuffer campaign that was, um, talked about, let's see here, back in May or so.

[00:12:26] Jenn Gile: I think maybe Socket found the Gem Stuffer campaign. And, uh, not a guarantee that it's the same threat actor or the same campaign, but similar vibe. Um, and these packages are not necessarily malicious, but what they're being used for is a means of hiding exfiltration in gems, and we've seen threat actors use other technologies in similar ways, um, to evade detection.

[00:12:54] Jenn Gile: So let's rewind. We had, um, uh, uh, crypto wallets became big, you know, in the last year of DPRK hiding payloads in crypto wallets because they, um, look like regular traffic. Presumably what's happening here is these are commits that contain data, right? That the, the way that these are getting exfiltrated is through these commits to projects.

[00:13:24] Jenn Gile: What are you seeing with this?

[00:13:25] Paul McCarty: Yeah. What they are is they're actually net new, uh, packages. They're net new RubyGems packages. So basically, um, this campaign that Socket found several months ago, the, the GemStuffer campaign, was really, um, similar to Shai Hulud and TeamPCP, where what, what it... For Shai Hulud and TeamPCP, what they would do is they would, they would steal all your credentials, they would compress it, and then they would create a net new repository with a name, and that just allowed the threat actors themselves to go and search GitHub, find those, those exfilled payloads and pull them and, and then, you know, use those credentials.

[00:14:02] Paul McCarty: This is similar to that, as I understand it, in the sense that this was targeting the UK government, um, and it was exfilling the contents of those compromised systems as RubyGems packages. Which is like, seems like there could more efficient ways to exfill data, but you know, hey, it's, you know, innovation's always interesting, I suppose.

[00:14:27] Paul McCarty: Um, this latest wave, again, it's not for sure because the payloads just aren't there like they were in the first one. Like, I went and inspected some of the payloads from the first wave of GemStuffer, and sure enough, it looks like exfilled data, right? There's some other stuff in there too as well, but... And, and it kinda, it's different from, from package to package, but there was obviously, in many of those packages from the first wave, exfilled data in them, which, you know, leans towards this theory that this was exfiltration from the targets.

[00:14:56] Paul McCarty: In these new packages, I couldn't find any exfilled data, but they're still there. They're creating them, and the na- the naming construct is, is very similar or the same. And so the, the expectation. So I reached out to the RubyGems team and trying to get some clarity and, and around that. Um, uh, so maybe more to come on that in the future, but I don't think it's a, it's a big high impact thing.

[00:15:16] Paul McCarty: It's just, like, a lot of packages when we don't really know why, and that's always a concern, right? When you're using, when you're seeing somebody use automation like that, like, just because the first shot misses doesn't mean that the second shot isn't gonna hit. So we wanna, you know, we wanna try to understand so we understand if there's something we need to protect against, um, going forward.

[00:15:36] Paul McCarty: Is that a good segue to our other

RubyGems Was Leaking User API Keys for Years

[00:15:38] Jenn Gile: that's a good segue to our other one. I feel like this is like the wacky news, like truth is stranger than fiction. Um, what you shared with me as we were getting ready to record is, um, RubyGems has been leaking user API keys for years, and this was an unintentional, uh, flaw that they corrected and they're notifying people about.

[00:16:03] Jenn Gile: But, uh, I think like the TLDR is if you use RubyGems and you've got API keys in there and you haven't gotten a notification, maybe better safe than sorry, you know, go ahead and rotate. But, uh, Paul, you know this through some, uh, networks of yours and it's, you know, to some extent public knowledge. So, um, yeah, share what's going on there.

[00:16:23] Paul McCarty: Yeah. I mean, the, the GHSA is out, the GitHub Security Advisory is out. Um, I don't know if there's-- it sounds like there might not be a CVE, but, um, yeah. So basically my mate Luke, um, down, he's actually near where I am right now. But, um, uh, you know, he works for Truffle, and Truffle identified that, um, it looked like there was, um, some caching of API credentials, um, in the RubyGems.

[00:16:48] Paul McCarty: Um, only, uh, y- you can only find it-- certain older clients were, were doing this because, uh, you had to ask for the right-- you had to ask it for the right way, so you had to, um, you know, not everybody was getting it. Um, but, uh, the point is that under the right conditions, unfortunately, the, the CDN was caching those API credentials, um, so that, you know, exposing those and people were getting somebody else's API.

[00:17:14] Paul McCarty: Um, so imagine trying to push packages to RubyGems and you're like, "Hey, how come I can't push this package?" Right? And then you go and do like a RubyGems list and you're like, "Wait, that's not the name of my packages. Wait, this is somebody..." And then you go and look at them and you're like, "Hey, that's, that's Gem's package.

[00:17:30] Paul McCarty: Why, why am I seeing Gem's package?" Um, that's the kind of thing that could, could happen out of this. But anyhow, RubyGems, um, handled it. They jumped on it really, really quickly. Um, just big shout-out to them. Um, super impressed with having dealt with NPM and other ecosystems for years where it's not as responsive.

[00:17:48] Paul McCarty: I s- and I said this to the RubyGems team. I was like, "You guys crushed it." Like, this is the best response I've seen from a, from a registry ecosystem, um, team, volunteer or otherwise, um, ever. So big shout-out to them. They fixed it, um, and they're letting customers know right now and they, you know, they're disclosing it.

[00:18:06] Paul McCarty: It's already public now, so, um, big shout-out to Luke. Um, I don't know if he's listening today, but, um, you know, that was entirely on him. Um, so good on him

[00:18:15] Jenn Gile: Yeah. Uh, always good to hear about good incident response, responses from, uh, the open source ecosystem. Okay, last topic.

[00:18:25] Paul McCarty: I actually, I wanna say, I wanna say

[00:18:27] Jenn Gile: are gonna say, "Okay."

[00:18:28] Paul McCarty: wanna say one more thing. I think it's important because, like, when this kind of thing happens, we have this network, right? And you reach out to your network and you figure out the right people to tell. And that just kind of came together really, really well here, right?

[00:18:39] Paul McCarty: That I know some of the people on the RubyGems team and, you know, so this is the kind of thing I really would like to put back out there. If you're doing disclosure on either side of that, try to find those people that can bring the conversation together as quickly as possible and as powerfully as possible, right?

[00:18:54] Paul McCarty: If you're just sending something to an email and it... and you're not hearing back much, well, maybe that's because you haven't gone and done what you need to do, which is, you know, reach out to people inside your network if you think you can put that together. So

[00:19:05] Jenn Gile: Yeah, it's a great example of, like, the real value of a network beyond career progression. Okay, for real, for real, CrashStealer.

CrashStealer: A macOS Infostealer With Multiple Tracks

[00:19:05] Jenn Gile: Um, we teased last week that we would be talking about macOS malware, which is not something we really bring up a whole lot. And in part that's because, um, we don't see a lot of malware that targets specific eco- ecosystems.

[00:19:28] Jenn Gile: A lot of times it's more agnostic. But our friend and, uh, top contributor to open-source malware threat intel reports, Ties from Jamf, um, published a really great report recently on this campaign he's called CrashStealer. What it is, is it's a novel, uh, malware info stealer. It's a C, C++, um, and it impersonates Apple's crash reporting framework to harvest stuff.

[00:19:55] Jenn Gile: So it's harvesting credentials, keychain data, you know, the usual stuff, and then it's exfiltrating it. Um, Paul, you took a look at this after, um, Ties published his blog and, um, you know, it's always interesting to see the way that these things build, so you did some building on the work that he did. And, uh, to kind of summarize, uh, sort of three discoveries that you made, um, basically, uh, you discovered that there's, uh, a second and a third track to this, that it is not just CrashStealer, but that this threat actor, uh, has other...

[00:20:34] Jenn Gile: What's the right way to say? Pans in the fire? Pokers in the fire? I don't know. Something's, something's on fire.

[00:20:40] Paul McCarty: What other weapons in their

[00:20:42] Jenn Gile: Yeah, something else is going on. Um, so one of these other ones is, or a RAT, a remote access Trojan. Um, after Ties published his article, um, the threat actor did, uh, clean up some of the CrashStealer stuff, some but not all, um, and very, very quickly spun up, um, a new track.

[00:21:04] Jenn Gile: So we've kind of been holding off publishing. Um, we wanna make sure that we, uh, can support the research on this without, you know, burning the, the infrastructure and having them go underground again.

[00:21:20] Paul McCarty: I think this is just a really unique story, and the reason that we've kind of held off on publishing it is that I think that the story that I wanna tell is about in this new world that we live in with AI and access to, you know, weapons, cyber weapons, software supply chain in this case, you know, the, what used to be true isn't really true as much anymore.

[00:21:41] Paul McCarty: So what we're, what we're seeing right now is we're seeing a single threat actor, which, uh, which is obviously not a single human being, right? But we're seeing a single threat actor in a campaign actually using many different totally unrelated malware strains in their, in their... And it's just I've never seen this before.

[00:21:58] Paul McCarty: One goes away and another new one comes in. You're like, "What just happened? Did I just go out of one dimension where that was true and now into another where this other one...?" Um, I, and so I think that's the thing that really kind of sticks with me is that, you know, whether this threat actor is buying these things from somebody else and just buying many multiples of them, right?

[00:22:18] Paul McCarty: Or if they're creating them themselves, or they're taking old code and making it new again, a la TPCP and MyESMA and stuff, who knows? But I've never seen one threat actor group, you know, run through so many massive, big, totally independent, you know, weapons of mass destruction as these guys are. So I think that's the thing that stands out for me, Jen

[00:22:40] Jenn Gile: Yeah, and I think like you said toward the beginning, this kind of, um, pivoting, you know, ability to be this diverse, you know, it's what, like the malware industry's EGOT award or something like that, you know, they're, they're, they're winning multiple categories here, um, is potentially being traced back to the way that LLMs are making this easier to develop quickly.

[00:23:10] Paul McCarty: And, and we're seeing this echoed across, you know, as I talked about something totally different earlier, at the same time we're seeing the same thing here, which is like everywhere we're just seeing the number of net new, novel new info stealers, which all you... If you look hard enough at them, they all have the same kind of core, right?

[00:23:27] Paul McCarty: They all are born from the same Adam and Eve or that same Eve, right? But people are just iterating on these so quickly and so fast and so many different new, um, info stealers out there in particular. Um, they're just, uh, it's like Tribbles. They're just, um, bam! I just dropped a Star Trek

[00:23:46] Jenn Gile: It's pretty good. I, I saw a reference to Gremlins the other day and, uh, same, same vibe. Don't get 'em wet, um, or don't give 'em water or something. I don't remember.

[00:23:57] Paul McCarty: Don't let them replicate. Which, whichever, don't let them replicate. Uh, yeah, it's crazy

Info Stealers 101: What to Look For

[00:24:03] Jenn Gile: Um, so why don't we... We've got a little bit of time and, um, we did have a request from the community to kind of go a little one-on-one on some things. So maybe this is a good opportunity for us to talk about, about info stealers, because not all malware is info stealers. So like, what are some of the characteristics that you look for in an info stealer?

[00:24:26] Jenn Gile: Um, how do they get assembled? Um, yeah, what, what do you feel like is kind of a good base level of knowledge for people to have about these?

[00:24:35] Paul McCarty: Okay. We talk about info stealers like they're like a class of thing, and they, they are, but they're not. Um, so like the... What I'm seeing is I'm seeing ultra-simplistic, totally in the clear, you know, 50-line code info stealers. And then I'm over here, I'm seeing DPRK massively obfuscated six-stage complex things also, you know, using info stealers.

[00:25:01] Paul McCarty: So the, it's a, it's a vast kind of ecosystem, but I think that first group where people can basically just go to an LLM and say, "Hey, create this thing really quickly," and just drop it in, this is where I'm seeing the most expansion, right? And so what you're looking for in an info stealer is like, what is it targeting?

[00:25:19] Paul McCarty: Is it specific to a, you know... Is it, is it focusing on just crypto? Is it focusing just on Solana? Um, is it focusing on at, on... Some of them really, really focus on AWS or Azure stealing those creds, and you can tell then that the intent for the author was, you know, that's what they want. Um, so you're looking for what it's stealing, and then you're looking for what does it do with it.

[00:25:41] Paul McCarty: How, how does it exfil? And that you always have that exfil component, 'cause that what is a bad guy, bad guy creates, steals something, and they gotta have, take their loot, and they gotta do something with that.

[00:25:52] Jenn Gile: Gotta put it somewhere

[00:25:53] Paul McCarty: gotta put it somewhere. And so, you know, we've built a whole system at OSM, um, using our Kill Chain technology that basically takes that exfil, uh, point and kind of works backwards towards the entry point and figures it out.

[00:26:06] Paul McCarty: It's similar to reachability for, um, vulnerability analysis, like identifying reachability. The idea behind reachability is that figures out if the vulnerability in a piece of code and, you know, at the function level or wherever is actually exploitable, right? Can you actually get to that vulnerability if you call it the right way?

[00:26:25] Paul McCarty: In a similar way, Kill Chain says, you know, what, what's the... It's really what, what the attack path. That's really the... It's the execution order ultimately of the malware. So you can just ignore the other files that are there. And, you know, a lot of these threat actors are just throwing hundreds of thousands of files to hide their shits.

[00:26:42] Paul McCarty: But if you know how to just follow the, the, the execution order, it's relatively easy. And so if you find the exfil point and work back from that, it's been very successful

[00:26:53] Jenn Gile: Et voila.

[00:26:55] Paul McCarty: Voilà

ChainVeil and ViteVenom Are PolinRider

[00:26:55] Jenn Gile: Uh, okay. Surprise topic. Uh, it's been such like, I feel like it's been a really long week. I forgot that I published some research on Friday about PolinRider. And so why don't we wrap up on the PolinRider stuff? Uh, and I think this is a, a complicated but not complicated situation. So I read, uh, some research last week that was published by the team over at Checkmarx, where they published a breakdown about a supply chain campaign that they called, uh, ChainVeil, and then a follow-up to that that was ViteVenom.

[00:27:30] Jenn Gile: And honestly, the Vite part is what caught my mind 'cause I was like, "Oh, a lot of people use Vite. I should see what's going on over in Vite." And I read through it, and something really stuck out for me in the IoCs that they listed. Uh, they specifically listed Tron, Aptos, and Binance, uh, blockchain addresses.

[00:27:49] Jenn Gile: And I thought, "Oh, that particular combination, you know, the three of them together, that's very familiar. We've been tracking that since the beginning of the year with PolinRider." And

[00:28:02] Paul McCarty: before

[00:28:04] Jenn Gile: yeah, even before.

[00:28:05] Paul McCarty: Yeah

[00:28:06] Jenn Gile: Um, and it's, you know, maybe we can talk a little bit again for, uh, people who aren't familiar with blockchain, uh, multiplexing.

[00:28:14] Jenn Gile: You know, when I tell people crypto wallets can be involved in, uh, malware, they think of it more like, "Oh, the crypto wallets are being stolen." But in fact, they're being used as a way to hide traffic, uh, and data being exfilled. You know, again, like the gems, like, um, other things. They, they're using that as a part of their, uh, C2 infrastructure because it looks like legitimate traffic, and this is what makes it so hard for things like EDR to catch them.

[00:28:45] Jenn Gile: Um, anyway, long story short, I looked at the IoCs for this ViteVenom ChainVeil, um, set of something like 13 packages that were published, um, between like July, June/July timeframe. And wouldn't you know it, uh, they had five shared IoCs with, uh, your PolinRider research, Paul. So, um, some keys, some wallets, an Aptos address.

[00:29:09] Jenn Gile: Um, they were byte for byte identical. There's, uh, kind of no doubt here. This is not, uh, somebody else got ahold of this infrastructure and is running a totally unrelated campaign. This is Lazarus Group, um, executing their PolinRider work. And, you know, we were just talking last week about PolinRider and the huge number of new compromised repositories that you discovered, and we talked about how those repositories end up getting discovered d- poisoned, sorry, brain.

[00:29:42] Jenn Gile: I haven't had my second coffee today. Uh, we talked about they, um, one of the ways they compromise developer repositories is if that developer consumed something malicious in the past. And so I would hypothesize that these, um, typosquats that Checkmarx discovered are part of that campaign to get people to consume poisoned packages to then do whatever it is that they've got planned with their whole PolinRider orchestration stuff

[00:30:15] Paul McCarty: Yeah. I mean, so I think the, the first thing is that PolinRider is, you know, we talk about PolinRider like as a campaign, um, and it is, but it's also an evolution of a set of North Korean threat actor kind of, you know, TTPs. So for example, in 2025, you know, we saw the advent of ether hiding, um, which is basically using specific blockchains like Aptos and Tron, which the, the, the chain...

[00:30:44] Paul McCarty: You know, blockchain is immutable. When you put something there, the whole point of it is that, you know, that, that you can't change that, right? But those Tron and Aptos, this BSC, um, uh, Binance thing have these little kind of memo things that you can change, and those things are immutable. So when you make a transaction, you can basically buy, excuse me, buy your ability to make a change.

[00:31:05] Paul McCarty: And that's where DPRK is hiding their payloads, 'cause otherwise they... When the first version of ether hiding, they weren't doing that, and then, you know, they put their payload there and everybody can see it, and then it couldn't change. And then you went like, kind of, you know, puts it... It's too public. So then they figured out the memo thing.

[00:31:21] Paul McCarty: So we have to d- make a distinction between ether hiding and this, this, uh, TTP versus PolinRider, which is really this human botnet that you and I are, are talking about, where DPRK has persistence on thousands or tens of thousands of developers' machines based on either, you know, fake recruiters or, or, or just because as this has grown, a lot of people have been compromised now just when they pull open source.

[00:31:47] Paul McCarty: I've, we've, we've been disclosing this to open source projects, and they've been removing these things and whatnot, but... So a lot of people are getting compromised a lot of different ways, but the point is that PolinRider is really this, like, movement, this campaign where it's like, has access to all these developers and it's using it to do more bad stuff.

[00:32:04] Paul McCarty: That's PolinRider in a

[00:32:06] Jenn Gile: Yeah. Helpful. Okay, we're at a little over half an hour. We hit a lot of topics today.

[00:32:13] Paul McCarty: Holy shit we

[00:32:16] Jenn Gile: We'll cut that. Uh, yeah, busy day. Uh, so we'll go ahead and wrap up here. Um, if you're gonna be in Adelaide next week for BSides Adelaide, hit up Paul. And another plug, if you're gonna be at Hacker Summer Camp, let us know.

[00:32:29] Jenn Gile: Uh, we'll be there all week. We've got now three talks during DEF CON. Uh, Paul, you've added a panel in the Cloud Village on, uh, MCP servers, I think, malicious MCP servers. Yeah, that should be interesting. Yay. All right, have a good week everyone. Good weekend

[00:32:44] Paul McCarty: Thanks for listening, people. Appreciate it. Cheers