BLOG
The OpenSourceMalware Show #18
Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads
By cb482791-4ef1-4762-96ad-b0ca4bdd538e ยท
The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.
This week we talked about:
Rust arrayref compromise tied to DPRK infrastructure: A compromised maintainer account published malicious versions of the arrayref crate, along with internment and append-only-vec, adding a typosquatted build dependency that downloaded and executed a remote binary at compile time. arrayref alone has more than 245 million lifetime downloads and sits in roughly three quarters of all Rust environments. Wiz Research has tied the campaign's infrastructure, including a shared C2 endpoint pattern and overlapping IP ranges, to the same DPRK actor behind the Mastra and Axios npm compromises.
StubMaker spreads from RubyGems to npm: What started as a RubyGems typosquatting campaign targeting bundler, i18n, rake, and activesupport turned out to share byte-for-byte identical payloads with a separate 40 package npm typosquatting cluster targeting axios, chalk, commander, lodash, react, and typescript. Both campaigns deliver the same 22MB Rust loader and embedded Go infostealer, confirmed by matching SHA-256 hashes, giving one threat actor two independent paths into any organization running both a Ruby and a Node stack. There's also evidence that this campaign hit the PowerShell ecosystem.
DIY binary payloads make a comeback: Paul has seen a sharp increase over the last two weeks in software supply chain attacks bundling compiled binaries (C++, Rust, Go) instead of sticking to the interpreted languages that dominate malicious open source. The theory: less experienced threat actors are following old malware-writing conventions, possibly with an assist from AI coding agents, without realizing that shipping a binary inside an npm or RubyGems package is itself one of the biggest red flags an analyst can ask for.
PolinRider reinfection wave using NullReceiver: We're still continuously seeing developers talking about getting reinfected with PolinRider. This latest iteration swaps out EtherHiding for NullReceiver as its stage two hiding method, and Paul and Jenn walk through why victims keep getting reinfected even after they think they've cleaned up: the malware lives on the developer's machine, not just in the repo, and it can commit to Git history without leaving an obvious trail.
Resources
(blog) Rust Supply Chain Attack on arrayref, Significant Overlap with DPRK Campaigns
(webpage) arrayref crate threat report
(blog) StubMaker RubyGems Campaign Delivers a Windows Infostealer
[00:00:00] Jenn Gile: Hello, hello. It is Thursday, August 20th. Uh, we have a kind of last minute list of things to talk about. Hot breaking news. Uh, there was a compromise in the Rust ecosystem that we're gonna get into. We're gonna talk about some research that we did earlier this week on a dual ecosystem compromise in NPM and Ruby, and, uh, a little bit, uh, around binary payloads.
[00:00:33] Jenn Gile: Paul, where do you wanna start?
[00:00:35] Paul McCarty: Oh, oh, just pick one. We're yo- we're YOLOing it today.
[00:00:40] Jenn Gile: YOLOing it.
Rust arrayref compromise tied to DPRK infrastructure
[00:00:40] Jenn Gile: So, let's, let's- Why don't we start with the Rust one since I know you were looking at that right before we got online. So to kind of just, uh, summarize in brief, um, it was discovered today that a maintainer, uh, D Roundy, Drundy, I don't know how you pronounce it.
[00:00:59] Jenn Gile: D-R- D Roundy,
[00:01:00] Paul McCarty: yeah ...
[00:01:00] Jenn Gile: yeah, uh, was compromised by threat actors in an account takeover. Um, they did something that we've kind of generally seen in the account takeover playbook this year, where they didn't actually push malware in the existing, uh, legitimate packages, but what they did instead was they published, um, six net new packages that were all malicious and then, uh, linked those to the existing packages as malicious dependencies.
[00:01:32] Jenn Gile: So again, if you're scanning the top level package, everything looks fine, but if you're not looking at the dependencies, uh, then you wouldn't necessarily know that you were pulling in malware. Um, so we've published on our LinkedIn, and we'll, um, share some more details, the, uh, IoCs to look for. There's a nice little script from, uh, Rust that can help you find out if you're using any of these packages.
[00:01:59] Jenn Gile: Um, Paul, what do you, what do you wanna share? What do you know so far?
[00:02:03] Paul McCarty: Yeah. Well, so the interesting thing is this actually dropped last night before I was going to bed, and so I stayed up late, um, working on it. So they've been in, they've been in open source malware... Well, most of them have been in open source malware because like all attacks, you know, when the initial word came out, we only thought this was, like, two packages.
[00:02:22] Paul McCarty: Um, and then of course over, um, we realized there was more, yada, yada. But, um, yeah, you're right. This follows kind of the, the NPM kind of playbook, and we'll get to that in a second because I've got something I haven't re- 'cause we're YOLOing today, I didn't even send Jen this link from Wiz. But, um,
[00:02:40] Jenn Gile: basically- No, I actually did see the Wiz one, I just didn't have time to read it.
[00:02:43] Jenn Gile: Oh, did you? Yeah. Okay. Cool, yeah, yeah. I was doing a little research before the show, so I, I think I know what you're gonna talk about.
[00:02:49] Paul McCarty: Yeah, cool. Sick. Um, yeah, so basically this attack compromised, uh, one maintainer and it compromised three of their existing legitimate packages, one of which is arrayref, which is a very popular Rust package.
[00:03:01] Paul McCarty: It's been downloaded 250 million times. Um, it's downloaded several million times a week. It is so popular that it, that by some accounts, I saw somebody say that it was in 76% of Rust projects. I have not verified that, but let's just, let's just, it's safe to assume this is a very, very popular package, right?
[00:03:19] Paul McCarty: So there's a, there's probably a better than even chance that, that, uh, or wor- worse than even chance, if you think about it that way, that you've got this in your Rust project. Um, and yes, it was up for 90, 90 minutes. It was online for 90 minutes. Um, but some of the ancillary packages were up longer. Um, and so, you know, total time.
[00:03:41] Jenn Gile: Anyhow, all right.
[00:03:43] Paul McCarty: So when I was looking at this last night, I, I thought to myself, you know, I was sleepy and I was like, "This kind of feels like other things that I've seen." But then I went to bed, and in the meantime, um, Rami and the Wiz team has, have come out with a blog post basically tying this attack, this Rust arrayref attack, to, um, the same DPRK North Korean threat actor that's behind Mastra and- Oh
[00:04:10] Paul McCarty: some of the other... Yeah.
[00:04:12] Jenn Gile: Okay.
[00:04:13] Paul McCarty: Now, and they're, they're basing this on a couple of things. First, you know, the look and the feel of TTPs. Like I said, I, my spidey sense last night was going off, like, this, this feels-
[00:04:24] Jenn Gile: Yeah, why don't you talk a little bit about it? 'Cause the, um, intel I have is pretty thin. What does the malware do?
[00:04:31] Jenn Gile: What's, what's unique about it- Yeah ... other than this pattern that we're seeing of a direct dependency calling a transitive? What can you tell us- Yeah ... about the malware?
[00:04:39] Paul McCarty: And, and I think that's the first thing. It's a, it's unique where they add the, that's, that follows the kind of the, um, the Mastra playbook.
[00:04:47] Paul McCarty: Um, what are the... What's the other group? Let me just really quickly here look at what's the other group of those NPM packages that all follow? I'm trying to remember. They all blend together now, right? So it's like, um- All right, well anyhow. Uh, so yeah, what does the malware do? Um, it is not focusing on CI, continuous integration.
[00:05:05] Paul McCarty: Does not, it's... This is focusing on smash and grab on an endpoint. Um, and so, um, it's been kind of modified to do that better. So stripped out a lot of the things that were there for worm versions of, of... The malware you would typically see like this in, in worms, a lot of that's been stripped out in this case.
[00:05:27] Paul McCarty: So it's an info stealer, it's a crypto stealer, it's fast, it's efficient, it's not great, but you know, I mean, I, I've already seen people say that they were compromised by it, right? So the reality is that unfortunately it was, um, it was effective. And when you... K- getting back to your question about what does it do, when you zoom out a little bit, it looks really, really similar to these like B grade DPRK, B and C grade DPRK campaigns that we see all the time.
[00:05:56] Paul McCarty: Well, B grade. Um, so-
[00:06:00] Jenn Gile: Like, is this similar malware to what you see in DPRK typosquats, or is it different from what you tend to see there?
[00:06:07] Paul McCarty: Yes, it is, it is very similar. Uh, and so, you know, because there's this whole pantheon, this whole like kind of grouping of DPRK all the way from the low-end stuff, which is really simplistic and stuff that's built to be brought in from other packages, and then there's the big complex packages that have like the six, seven stages in the kill chain, this feels like it's somewhere in the middle.
[00:06:31] Paul McCarty: Um, and so, uh, that's part, that's partly what Ro- Rami talks about in this, this article. Um, I loosely agree with, with the things that they've said. You know, I haven't read it... I mean, I've, I've read it a couple times, but uh, I think the most important thing is they have tied it to some specific shared IoCs.
[00:06:51] Paul McCarty: And I think the look and the feel of the TTPs, that spidey sense that I got, this is what you get as a researcher when you s- you smell something. You're like, "Oh, there's some blood in the air right here," and you, you know
[00:07:00] Jenn Gile: it's leading- Well, it's like, I think we'll actually talk about this later, what we saw with the Rust and NPM cam- or uh, Ruby and NPM campaign earlier this week.
[00:07:09] Paul McCarty: Right.
[00:07:09] Jenn Gile: Yeah. Just kind of flipping through, uh, the Wiz blog, and I see it's got shared C2 endpoint pattern, not exactly the same endpoint, uh, as with the Mastrat campaign, so that's interesting. Um, like you said, sometimes these patterns, uh, may not 100% match, but it's close enough and unique enough that we can kind of like, you know, let our eyes go fuzzy and be like, "Oh yeah, those things look the same."
[00:07:36] Paul McCarty: Yeah, and one of the things that we're seeing a lot, and we saw this with, with TeamPCP and other non-DPRK threat actors, is we're start- there's starting to be a move away from IPs at the, at the earlier stages of the kill chain to, like, the use of these throwaway domains. And I think part of that is because DPRK and other threat actors have found ways to buy domains from registrars using crypto, and that's why I was, I was bird-dogging in GoDaddy earlier- Mm-hmm
[00:08:04] Paul McCarty: oh, sorry, last week, trying to figure out is, is there a way now to buy... And it looks like there is a way now to buy domains in GoDaddy's registrar via crypto through these other payment processes. So we're seeing an increase in this, which is good because they're great little indicators to have, right? Um, but, uh, it's just, you know, when you're watching the kind of tradecraft, this does feel like DP- DPRK-ish.
[00:08:28] Paul McCarty: Is that a, is that a authoritative attribution statement? No, it's not.
[00:08:34] Jenn Gile: Yeah. Well, it does say in the Wiz blog that, um, a victim has reported C2 traffic to an IP that's also from the Axios attack back in, what, March or April. So- I
[00:08:48] Paul McCarty: saw that ...
[00:08:49] Jenn Gile: yeah, we're seeing multiple indicators of shared threat actors, and maybe this is a good place to pause.
[00:08:56] Jenn Gile: When the Axios attack happened, when the Mastra attack happened, these were unknown threat actors at the time. Uh, they did happen around the same cluster as major account takeovers by TeamPCP. They were not claimed by TeamPCP. Uh, but we've seen, um- People attributing those attacks to North Korean threat actors with a degree that, um, of credibility that we trust, in addition to Chalk and Debug.
[00:09:27] Jenn Gile: So we've got a pattern here where North Korea is effectively taking two different, um, strategies. Like, if we were talking about this as a company and their go-to-market strategy. You know, their, their first go-to-market strategy was that typosquatting, contagious interview, now PolinRider. Very targeted on getting into an individual developer's account, getting persistence on an individual developer's machine, quietly spreading, trying to stay under the radar.
[00:10:00] Jenn Gile: The other, uh, part of their go-to-market strategy are these higher profile smash-and-grab account takeovers where they know that they're not going to, uh, maintain control for very long, and they're not going to, uh... They're, they're... This is not a typosquat that hangs out for months or, you know- Right ... people don't know necessarily that they consumed something bad for months.
[00:10:31] Jenn Gile: So interesting to see them using both tactics. Not necessarily surprising. Um, both tactics have merit. The things that we do to protect ourselves against an account takeover broadly have no, uh, protective, uh, elements for this other, you know, typosquatted type package attack. Yeah. Whereas, you know, if you're focused on, I don't know, um, making sure you're only consuming packages from legitimate sources, then, you know, you're more likely to have that implicit trust in a package like the arrayref that got compromised today.
[00:11:13] Paul McCarty: Yeah, I mean, I totally agree. I mean, I think we've, we've said it before, and the reality is that the DPRK, you know, spreads themselves, you know, they're like, they're like Palmolive. They've got products in, in all the areas. It's like when you call, when you call Samsung, "Press one for a microwave product.
[00:11:33] Paul McCarty: Press two for an automotive product." I mean, DPRK has got you covered. If you want sneaky and long-lived, they got that. If you want short-lived,
[00:11:40] Jenn Gile: smash-and-grab- Never mind the IT workers and everything else that they've got cooking ...
[00:11:43] Paul McCarty: Right?
[00:11:43] Jenn Gile: Right?
[00:11:44] Paul McCarty: Right. They are very adaptive, and they are spreading themselves across the whole...
[00:11:48] Paul McCarty: And I love your use of go-to-market, 'cause I coined the term last week, go-to-target. This is... They, they found their, you know, their cos- That's why they use all these campaign marketers. I'm sorry, campaign markers. They're trying to figure out what are the most successful ways that they can compromise people,
[00:12:03] Jenn Gile: um, also- Yeah, you gotta have your, uh, metrics so you know what's successful.
[00:12:08] Paul McCarty: Right? DPR- Pyongyang has got its K- KPIs, baby.
[00:12:13] Jenn Gile: Okay. Shall we move on-
[00:12:17] Paul McCarty: Pass it on ...
StubMaker spreads from RubyGems to npm (and maybe PowerShell)
[00:12:17] Jenn Gile: to StubMaker? Yeah, let's do it. Let's do it. Okay. Uh, to summarize, over the weekend, uh, we did some research specific to RubyGems. Uh, we found a cluster of packages. It started with two packages initially. That's what you sent me when we started our write-up.
[00:12:35] Jenn Gile: And then as I started poking at it, I was like, "Oh, wait." Uh, they've managed to resuscitate, revive one of these packages and spread even further. So long story short, um, a whole bunch of Ruby typosquats were published over the weekend. Uh, they managed to do it across multiple accounts. And, uh, a, a, maybe a trick that's unique to the Ruby ecosystem is when Ruby killed those first two packages, they seemed to figure out pretty quickly that they were malicious, you know, even at the same time as we were analyzing them.
[00:13:10] Jenn Gile: Uh, so they killed those two initial packages, but, uh, they don't seem to have a security mechanism in place to make sure a known malicious package doesn't get reactivated. And so the threat actor was able to create a new account, come back into Ruby and resuscitate one of these packages that had been taken down, and publish a new malicious version to that package that always should have stayed dead.
[00:13:41] Jenn Gile: So I thought that was some really interesting Ruby-specific behavior. The other thing, as I was looking at this campaign and looking at every package page side by side, is they were all, um, they had the owner account, and then they had the author account- Right ... listed. And the owner account, that's tied to an actual account with a login and everything.
[00:14:06] Jenn Gile: The author- A
[00:14:07] Paul McCarty: RubyGems account.
[00:14:08] Jenn Gile: Yes, a RubyGems account. The author is what I would describe as like a vanity label. It can be anything that you want. Uh, there is no mechanism to force you to make the author, you know, the same as somebody who is in the ownership group, anything like that. And so we had, you know, things like an owner with sort of a random string of letters and numbers, and then the author name would be something like- Blake Miller or Taylor Gray or Avery Collins or Quinn Parker.
[00:14:43] Jenn Gile: And at least to me being American, I saw those names in a, in a list and I was like, gosh, it's like they, they had like a random name generator targeting children of, I don't know, young Gen Xers or millennials. Like
[00:14:57] Paul McCarty: Uh, you know what I... When I saw those names, I thought somebody's created a random name generator based on the Country Music Awards.
[00:15:06] Jenn Gile: It could be.
[00:15:07] Paul McCarty: It seems.
[00:15:08] Jenn Gile: So I mean, there were some like very clear indicators that these were sketchy before you even pulled the payloads, but we proactively scan Ruby. So as things come into Ruby, we're looking at it. That's how your, uh, detection got set off. Yeah. So why don't you talk a bit about the malware and then we'll segue into the NPM part of the campaign.
[00:15:28] Paul McCarty: Oh my gosh. Like now you're putting me on the spot like I've, I've, I've forgotten how to-
[00:15:31] Jenn Gile: I know. Our brains have like wiped ... For- And that was four days ago. Why would we think about that?
[00:15:36] Paul McCarty: It, it was. Let me real qui- uh, let me just cheat here in the background and just, uh, bring up the blog post. I can remind myself.
[00:15:43] Paul McCarty: Um, I, uh, there we go. I'm, I'm here. Um, yeah, so I mean, I think the, the, all the things that Jen said, uh, are true. Um, this, uh, campaign, um, I'm trying to remember exactly how the... Oh, yeah, so basically they were targeting, um, i18n and, um, uh, a, a number of- Bundler ...
[00:16:11] Paul McCarty: yeah.
[00:16:12] Jenn Gile: Um, other reputable like well adopted, like active support was in there, Break-
[00:16:22] Paul McCarty: The vast majority of them were like simplistic I18, um, kind of, uh, you know, uh, just, uh, brute force kind of typosquats, right?
[00:16:34] Paul McCarty: Not particularly well thought out. But the... And Jen and I talked about this behind the scenes, that the, the malware itself was actually pretty decent, you know, for you, you... And, and that's, I think something that stood out about this is that, um, the, the typosquats themselves inside of RubyGems were kind of meh, but then the malware sitting behind it, um, uh, you know, was, was more mature than we were expecting based on that initial part.
[00:17:04] Paul McCarty: So, um, I think that, um, the, again, this kind of, you know, looked and felt at a high level DPRK-ish, not attributing this to DPRK. Um, but you know, the, the endpoints and the ports used and some of those kind of high-level tradecraft bits felt kind of DPRK-ish. But you know, I mean, that's not-
[00:17:30] Jenn Gile: No ...
[00:17:30] Paul McCarty: to say that other people aren't doing that, but you know, it was the kind of typical info stealer and, um, crypto stealer that everybody does now.
[00:17:38] Paul McCarty: Um, uh, I think it, it had a couple of functions in it that specifically looked for credit card, um, strings in, in files, which you don't see that often anymore. People don't really do that. Um, that kind of, that kind of, um, uh, grepping through files looking for things like that, or things that can get caught by, you know, even simplistic EDR, um, or, or antivirus.
[00:18:06] Paul McCarty: Um, so threat actors tend not to do it. But yeah, I mean, sorry, that's not like, not, not a super high, uh, quality analysis, but um, it did feel to- Well- Go ahead.
[00:18:20] Jenn Gile: Maybe we can go through what the malware does, uh, because I think it's a little bit unique in that it uses whatever language the package started in and then it goes into Rust- Mm
[00:18:34] Jenn Gile: and then there's some Go in there. Yeah. It's very specifically targeting Windows. So essentially it starts out with the victim installing the typosquatted package. Uh, Ruby has a mechanism that's a little bit similar to what we've seen in NPM and in VS Code, where it can let you automatically do some, a series of things without having an import or a require.
[00:19:02] Jenn Gile: So it's this, uh, ext conf, conf.rb. I'm not a Ruby person, so I don't know how you say that filename. But there's a special filename that essentially is kind of like an auto-install function. There's a hook from there, right?
[00:19:20] Paul McCarty: Yep.
[00:19:21] Jenn Gile: And then- Yep ... you know, a couple steps down, it's looking to see, you know, it's pinging the host and saying, "Hey, what kind of operating system are you?
[00:19:30] Jenn Gile: Oh, Windows? Hi, we'd like to, you know, stay here." Linux, macOS, uh, telemetry only and exits. But if it's Windows, then it downloads a Rust-based loader. Um- Yeah. I think- And something that was very, uh, specific there is it's a 22 megabyte file size, so that 22, let's, let's remember that and we'll come back to it.
[00:19:57] Jenn Gile: Uh, again, it's gonna detect, uh, WSL. It's gonna bridge out to PowerShell. It's gonna launch a loader that's a Go-based info stealer, and then it's exfilling a password-protected zip file.
[00:20:12] Paul McCarty: Yeah, let me jump
[00:20:12] Jenn Gile: in here. And I'm gonna let you talk while I let my cat out of my office- ... 'cause he's, he's not happy, so I'll be right back.
[00:20:19] Jenn Gile: You talk.
[00:20:19] Paul McCarty: Yeah, I mean, i- in the meantime, I've been able to remind myself of what was going on here. I just see so many different attack chains, kill chains, that they kind of all blend together, so I had to kind of remind myself. But I think, um, this was interesting because it did use, like, multiple stages.
[00:20:34] Paul McCarty: There's, like, five or six stages, and each one of those stages is actually written in a different language. So, like, the first loader, this 22 meg file, is, is Rust, right? But then inside of it, there's an embedded Go, uh, second stage. And that's where the info stealer kind of kicks off. Um, but there's also JavaScript components and there's Ruby components.
[00:20:54] Paul McCarty: Um, and I think that that Rust loader with the embedded Go, um, info stealer in it is a pattern that we're seeing a lot from DPRK. And so that's one of those things that just kinda made me feel like, oh, this kind of could be there. But then there's a bunch of things that don't align with DPRK tradecraft.
[00:21:11] Paul McCarty: For example- Well, like
[00:21:12] Jenn Gile: candidly, they are much better at typosquat targeting than what we saw with this campaign, and I'm not saying that means it's not them- Agreed ... but these were pretty bad.
[00:21:21] Paul McCarty: Yeah, and, and there's not, you know, you- bad guys are gonna emulate other bad guys, and right? So and, and the fact that the, the point I was just gonna make is that it pulls that, that 22 meg file from a GitHub repo.
[00:21:34] Paul McCarty: That's really unusual. Like DPRK traditionally doesn't want to pin and pivot off a specific GitHub repo because that's just something that I can watch. If you kill the
[00:21:43] Jenn Gile: repo, it's gone, right?
[00:21:44] Paul McCarty: Yeah, yeah, and it's also something that I can sit there and I can watch, right? Um, so that was unusual, and the fact that they didn't hide the loader, it's just main.exe, right?
[00:21:56] Paul McCarty: Excuse me.
[00:21:56] Jenn Gile: I'll also note that when we were looking at the obfuscation, and I'm gonna say obfuscation in air quotes- Right ... the, uh, IP address was kind of hilarious. All they did was take the periods out, so they had the bracketed IP address without periods and with spaces instead, and then with a join period after it.
[00:22:18] Jenn Gile: So, you know, anybody who's visually looking through there is like, "Ah, there's an IP address."
[00:22:24] Paul McCarty: Yeah. You know, so they, th- th- it's sending us these mixed signals, right? Like the IP address thing and like the fact that they're just sticking it clearly in a GitHub repo, the main loader, so it can get torn down.
[00:22:35] Paul McCarty: So here's a, here's something to learn by, bad guys. What you don't wanna do is you don't wanna make the first stage really easy to take down, because then all the other stages don't run, right? You can, you can get a little bit loose when you're down at stage four, stage five, but stage one you wanna be hiding, and that's why DPRK uses things like EtherHiding and NullReceiver in that second stage after the NPM package of the GitHub repo is because that's just, that's, you know, very effective at hiding and being, letting them be able to iterate.
[00:23:03] Paul McCarty: But another thing that I just thought about, Jen, was that like the, this, the mixed signals that this attack was sending us, it actually had a pretty well done, um, a bypass around the, the Google Chrome App-Bound Encryption, um- Yes ... control.
[00:23:17] Jenn Gile: It did.
[00:23:18] Paul McCarty: Which I think surprised a lot of people, like there are multiple people on LinkedIn and, and Twitter, you know, mentioned, oh, 'cause we've only started seeing that, um, these bypasses recently, and other people are doing it, so it's not like this is super unique.
[00:23:31] Paul McCarty: Um, but what it does is it makes it that much more powerful in, in stealing stuff out of the browser, right? It's bypassing this, this significant control that Google added in like 1.127 or something, or sorry, uh, version 127 a couple months ago. Um, so yeah, all in all, mixed bag, kinda looks like DPRK, kinda looks like vibe coding.
[00:23:55] Paul McCarty: Um, used all kinds of languages, right? And something I pointed out in my blog post is that this kind of casual polyglot, and if anybody's not familiar with this term polyglot, it basically means somebody that can speak multiple language, or in this case write multiple languages, use multiple languages.
[00:24:11] Paul McCarty: Well, people don't have to actually understand multiple languages anymore because Claude and Codex and whatever other agents they're using are writing all this stuff for them. So for whatever reason, they say, "Hey, write me a, you know, follow the pattern from DPRK and write me a Rust wrapper," right? Around the Go, an embedded Go and, or, or it's just following the patterns that it knows from the DPRK, who knows.
[00:24:32] Paul McCarty: Very, yeah, lots of mixed signals there.
[00:24:34] Jenn Gile: Well, speaking of languages, uh, maybe two days after we published this research, I was in LinkedIn, 'cause I'm in there way too much, and I saw somebody's post about, and I'll quote, "A 37 package typo squatting campaign on NPM." And so I always click when I see those kind of things.
[00:24:51] Jenn Gile: It was from somebody from OpenHack. And they, in the initial description described a 22-megabyte Rust loader carrying an embedded Go info stealer. And I was like, "Ding, ding, ding. That sounds awfully familiar." And- That seems like
[00:25:07] Paul McCarty: a pattern I've seen recently. Yeah,
[00:25:08] Jenn Gile: yeah, yeah. That's, that's very recent. So I took a, a second to compare it to your write-up.
[00:25:15] Jenn Gile: Uh, we pulled the payloads. It's identical. Um, the only difference being because it's npm and not Ruby, the, uh, firing mechanism is different. They took an advantage of the npm post-install scripts, which at this point are infamous, uh, in the community as a way to auto-install your malware. And then, uh, ultimately, I found a total of 40 packages that were associated with the npm branch of this attack.
[00:25:44] Jenn Gile: Uh, the shape here was actually slightly different than what we saw in Ruby. Instead of these, as you say, country music name generator names, uh, it was five different, uh, npm accounts that published this set of 40 packages. None of the names on these accounts are, look like real human names for the most part.
[00:26:05] Jenn Gile: It tends to be a string of maybe 10 to 15, uh, alpha characters or, you know, letters and then a series of numbers. Um, one of them is WhatIsThisAppLive20238261.
[00:26:23] Jenn Gile: Another one is
[00:26:27] Jenn Gile: FullBasketPropertyWebsite53A. Uh, so very different in terms of naming conventions, but same deal with the really clumsy typosquats. They were, um, targeting Axios, Chalk, Commander, uh, Lodash, and, uh, TypeScript. And there's probably, I don't know, 10 different TypeScript ones where they've transposed letters or added a letter and, like, it- I can see in some ways how somebody might, you know, fat-finger the keyboard and accidentally type one of these things, but still, it's a brute force style attack.
[00:27:01] Jenn Gile: Now, what I forgot to tell you, Paul, um, is one of the email addresses has some kind of like superfluous periods throughout the email address, and that's another thing that did remind me of DPRK because we've- Yeah ... seen that, uh, in some DPRK NPM accounts where they'll have a username and then their email address is kinda similar but has like random periods.
[00:27:28] Jenn Gile: Um, weird. So we know for sure that it's hit two ecosystems. I was chatting with someone from the Hacker News the last couple days about it, and he emailed me last night and he's like, you know, "Have you seen it cross into any other ecosystems?" And I was going to type no, and I haven't caught you up on this yet, so I don't know if you know what I'm gonna tell you.
[00:27:49] Jenn Gile: Um, and then I got tagged in a post overnight about the same campaign hitting PowerShell, and we haven't had an opportunity to take a look at it yet, but we're having multiple people say, "Hey, it's, it's the same shape, it's just in PowerShell."
[00:28:05] Paul McCarty: Yeah, and you know, the funny thing is I didn't even know that PowerShell Gallery existed.
[00:28:10] Paul McCarty: I was like, "Oh my God, a registry for PowerShell. Yay." Add it to the pantheon of Microsoft things that are f- probably far too insecure. Um, so yeah, we have yet to kind of go down that road and we're going to. Um, but I feel
[00:28:25] Jenn Gile: like I- I would say I have no reason to think they're wrong at this point. I'm seeing some screenshots in X.
[00:28:33] Jenn Gile: Um, it probably is in PowerShell
[00:28:37] Paul McCarty: I feel like I, last night before I went to bed, I feel like I saw one come in, um, in VS Code or one of the other ecosystems- Mm-hmm ... that was labeled StubMaker. So we're gonna, we're, we're gonna see these things. I mean, we typically do, you know, with many of these big campaigns that, you know, after the initial, uh, kind of wave, then we see additional stuff coming in.
[00:28:57] Paul McCarty: Um, so standby, there might be some other ecosystems to add to that list as well into that blog
[00:29:02] Jenn Gile: post. Well, something that we did not talk about is the role of AI potentially in this campaign. And, you know, as you and I talked about behind the scenes, we're not seeing the, uh, traditional hallmarks of AI-written code, but, uh, that it was hitting the number of ecosystems that it seems to at the same time, and in some cases, you know, rapidly evolving.
[00:29:28] Jenn Gile: It seems possible, you know, given the number of different languages and ecosystems, like you said, nobody's expected to be an expert in, I don't know, NPM, Ruby, and PowerShell
[00:29:42] Paul McCarty: Yeah, I mean, the, it makes sense that if you, you know, if you start out with an NPM or one of these high profile, you know, registries where things get taken down relatively quickly, you can take that same attack and just repackage it for some of these smaller, less, you know, with, with less volume, less volumous, anyhow, less popular or, or whatever ecosystems, repackage it there and maybe get, you know, some, a longer tail out of it.
[00:30:10] Paul McCarty: So not surprising.
DIY binary payloads make a comeback
[00:30:12] Jenn Gile: Mm-hmm. Okay, last topic. Uh, you've been telling me for a little bit now that you've been seeing an increase in what you're calling DIY binary payloads. So taking a step back, we don't actually see a lot of binary payloads in malicious open source. Typically, it's in an interpreted language.
[00:30:31] Jenn Gile: That's why things like halfs tend not to be very useful with malicious open source. Uh, you are seeing, uh, maybe like a little bit of a Frankenstein where some of it's interpreted and some of it's binary. So talk about what you're seeing.
[00:30:48] Paul McCarty: I mean, StubMaker is the perfect example. This, this is a great segue from the StubMaker conversation to here, where StubMaker had, you know, five or six languages used, um, in binaries in at least, uh, three languages, C++, um, Rust and Go.
[00:31:03] Paul McCarty: So basically, yeah, I've been saying on the podcast and in other places for years that like, you know, I, I have, I don't have to do a lot of dynamic or, or sandbox analysis because most of the stuff we look at is interpreted, and as long as you have a built for purpose, um, uh, s- static analysis harness, you know, you can kind of, you know, take care of 99% of it.
[00:31:23] Paul McCarty: But just in the last two weeks alone, I've just seen the increase in software supply chain attacks that are using, you know, bime- binaries in stages two through four or whatever. It's just increased dramatically and I've just spent a lot of time over the last two weeks doing stuff that I typically don't have to do, r- you know, reviving some of these, these skills from my heyday.
[00:31:45] Paul McCarty: But, um, I think this is evidence of a couple things. I think it's evidence of, first, the use of agents and LLMs to write or help write your malware. Two, because you're not a mature, uh, uh, open source malware or software supply chain malware writer, author- The way that you think that you have to hide your malware is by putting it in a binary and kind of following that traditional path, right?
[00:32:10] Paul McCarty: So you're new, you're like this newbie malware author, and you're looking at, you know, like VX Underground and th- this whole thing that tells you that you gotta build m- uh, binaries to hide your shit, your stuff, and y- that's what you do. Th- that's the pattern that you, you follow, right? Um, I... And I think the reality is those stick out like a fo- s- uh, like a sore thumb.
[00:32:30] Paul McCarty: When you see a NPM or RubyGems package installing a binary, either with that binary in the package itself, which makes it bloated, right, as we were just talking about with StubMaker, or downloading that, immediately downloading that from a URL or an IP, I mean, these are pretty big flags. So you might think that you're hiding it in the binary, but the fact that you're adding the binary itself is the biggest red flag.
[00:32:53] Paul McCarty: So, uh T- uh, tip to
[00:33:00] Paul McCarty: you Old school malware
[00:33:00] Jenn Gile: Yeah. Don't
[00:33:01] Paul McCarty: put binary in. Yeah. I'm gonna g- I'm gonna give you bad guys a little tip here, which is y- you don't use binaries. They, like, you think that they're helping you, and they're not, right? Dumb-dumbs. Um, anyhow, we'll leave it to that.
PolinRider reinfection wave and NullReceiver
[00:33:19] Paul McCarty: I, um, I also wanted to throw y- in classic YOLO style, I also want...
[00:33:19] Paul McCarty: And I think this is probably something we can talk about more next week, but Jen and I have been seeing the number of people affected by PolinRider, like, being reinfected. Just, I was checking that, that GitHub community issues today. I meant to tell you, I'm, I
[00:33:32] Jenn Gile: am subcr- subscribed to updates, and, uh, I was gonna read this one.
[00:33:38] Jenn Gile: Uh, I
[00:33:39] Paul McCarty: think this is- Yeah, please do ... uh,
[00:33:39] Jenn Gile: after new- I
[00:33:40] Paul McCarty: took a screenshot of it for exactly that purpose too as well.
[00:33:43] Jenn Gile: After nearly two months of inactivity, the malware has started pushing changes to all repositories and branches again. Womp, womp. That's my add- Womp, womp ... womp, womp is me. Um, they found that it's using, you know, an Ethereum address.
[00:33:58] Jenn Gile: Uh, it's that same reinfection cycle- Yeah ... that we've been seeing.
[00:34:04] Paul McCarty: But interestingly enough, this is the first time that we've seen NullReceiver used in... Well, actually that's not true. I think we have seen NullReceiver in the PolinRider, but it has not much, right? So this is clearly the use of NullReceiver at stage two, um, in, to replace EtherHiding.
[00:34:18] Paul McCarty: In fact, this kill chain, um, you know, when we initially saw NullReceiver at stage two, which is basically hiding the IP address for, for the next stage in, um, in the, uh, response, uh, the, the destination response, which didn't exist. Um, we saw EtherHiding in the next stage, right? So there was NullReceiver, then there was EtherHiding.
[00:34:40] Paul McCarty: We don't see that anymore. EtherHiding's gone, uh, and it's been replaced by NullReceiver. And so this is PolinRider, DPRK, is now using NullReceiver as a primary hiding methodology, um, instead of like EtherHiding. So, you know, gone are the days of EtherHiding.
[00:34:55] Jenn Gile: I think it's worth a quick how is this possible conversation.
[00:34:58] Jenn Gile: You know, you've got a person here in the GitHub community saying, uh, they, you know, I'm reading between the lines. They think they got rid of the malware. Two months later, it's back How does this happen? Um, how is DPRK pushing updates? How are they, you know, putting in new parts of their kill chain?
[00:35:16] Jenn Gile: Because obviously NullReceiver wasn't there two months ago. Um- Yep ... this comes back to the way that PolinRider works from a basic level is this is not a threat actor, you know, using your credentials 100% of the time, hanging out on your machine. So, like, maybe you have rotated your credentials, maybe you've even replaced your machine, but you go and, you know, accidentally reinfect yourself, uh, using your repo or the other way around.
[00:35:47] Jenn Gile: It's still hanging out on your machine. It's able to get whatever credentials you have locally, and the, I guess, brilliant part about this malware is it can make commits to your repo without leaving a trail. So you won't- Yep ... see a suspicious commit necessarily. Sometimes you will, but, um, sometimes you won't see a suspicious commit at all.
[00:36:12] Jenn Gile: Uh, they're able to hide that so that you can't just have an alert set up that says, "Hey, let me know if something new g- comes in here that I didn't authorize."
[00:36:23] Paul McCarty: Yeah. I mean, to say this a different way, what we hear again and again and again from these victims is that they're looking at their commit history in GitHub, and they are unable to reconcile in their brain because they just don't understand how it works, how they're looking at a Git c- uh, commit history that hasn't changed or it doesn't appear to have changed, and yet they're looking in a file and there's a new malicious payload there.
[00:36:46] Paul McCarty: They just can't comprehend that, and that's because of one thing. And the funny thing is that there's usually, like, an engineering, uh, misunderstanding or, uh, a, uh, InfoSec, SecOps misunderstanding. In this case, both of these, you know, personas don't have an understanding, which is that the Git commit history happens on your machine.
[00:37:07] Paul McCarty: GitHub just expresses that as a luxury to you, right? It just, it's just accepting the Git commis- commit history that's coming from your machine when you push up to origin. So what happens is DPRK is overwriting existing older commits, three years ago, five years ago, 10 years ago, it doesn't matter. They overwrite those, put the new malicious payload in there, then they wait for you to go ahead and do your work, and then you push it up again.
[00:37:33] Paul McCarty: And here's the other thing, and this is, uh, continuing, continuing our YOLO trend. DPRK has now found a way to infect NPM itself, the package manager. We will talk about this next week 'cause we gotta do a blog post about it. But the reality is that DPRK is ever-innovating in this space, and that's why PolinRider continues to be this just massive human bot network that keeps infecting people.
[00:37:56] Paul McCarty: So they buy a new MacBook, and they set it up, and they're infect- infected within a day or two, so it's crazy.
Wrap up
[00:38:03] Jenn Gile: Uh, on that note, uh, we've got one more podcast this month. Uh, we're gonna take a week break, and then Paul and I will be in Europe, uh, in early September. We're gonna be in, uh, Strasbourg for Underground Economy, so come say hi if you're going to UE.
[00:38:23] Jenn Gile: And then Paul, you're gonna be speaking at BSides, which one?
[00:38:27] Paul McCarty: Frankfurt.
[00:38:28] Jenn Gile: Frankfurt. BSides Frankfurt. So if you're gonna be- That is- ... at either of those events, come say hi. Let us know you're gonna be there, whatever. We'll give you a sticker. For sure. We'll talk about PolinRider. I think we're talking about PolinRider at both, right?
[00:38:40] Jenn Gile: I assume that's what you're presenting in Frankfurt.
[00:38:42] Paul McCarty: Yeah. Yeah, we are. Yeah. So, uh, uh, UE is September 7th through 10th.
[00:38:48] Jenn Gile: 7th through the 10th. Yeah.
[00:38:49] Paul McCarty: And Frankfurt BSides is September 11th. I can't forget that day. It's September 11th, so that's gonna be, um, that's gonna be an interesting thing to, to talk about, you know, in Frankfurt on September 11th.
[00:39:01] Jenn Gile: Yeah. All right. Everyone- Cool ... have a good one. This was a little bit longer than usual, but lots of interesting stuff to get into.
[00:39:07] Paul McCarty: Thanks. Thanks for listening everybody. Appreciate it.