BLOG

The OpenSourceMalware Show #19

TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts

By cb482791-4ef1-4762-96ad-b0ca4bdd538e ·

The OpenSourceMalware Show #19

The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.

This week we talked about:

This week we talked about:

  • TeamPCP arrests — Australian Federal Police and the FBI arrested Ruben Thomson (21) and Louis Gaebler (23) in Perth on TeamPCP-related charges. The arrests align with the OpenSourceMalware team’s longstanding assessment that TeamPCP was a very small operation, effectively one or two people, despite the scale of its attacks. Krebs’ reporting details the OPSEC failures (reused usernames and passwords, prolific unredacted social media activity) that led to their identification, and despite the technical complexity of the attacks, the financial payout was reportedly modest (around $20K). Jenn and Paul discuss what this could mean for other overlapping threat groups like Lapsus$ and ShinyHunters.

  • PolinRider’s persistence outlasts partial remediation — A look at how DPRK’s PolinRider campaign continues to reinfect developers who believed they’d already cleaned up. When a developer only removes the malicious payload files but not the underlying persistence mechanism (like a vscode-task.json trigger) or the RAT running on their machine, DPRK can push new payloads that ride along on the developer’s own legitimate package publishes. Paul and Jenn cover what’s changed in the kill chain: a new NullReceiver-branded payload, a persistence technique that overwrites the npm CLI binary itself so simply removing payloads from repos isn’t sufficient, and an expanding target list of JavaScript/TypeScript file types the malware will inject into. They close on why disclosing an infection to collaborators matters, since silent individual cleanup doesn’t stop reinfection through shared repos and contributors.

Resources

TeamPCP:

PolinRider:

TeamPCP members arrested in Australia

[00:00:00] Jenn Gile: It is Thursday, August 27th, and we are here with, I’m gonna call it breaking news out of Australia, which maybe is not a thing that we hear too often in the cybersecurity world. But, uh, good news, the Australian Federal Police arrested two individuals associated with Team PCP. Um, they’re two of the more, uh, perhaps active members from what it sounds like, and Paul, love to hear your side of this in just a second.

[00:00:30] Jenn Gile: But just in brief, um, it’s a 21-year-old and a 23-year-old, uh, Ruben Thomson, and, uh, the other suspect was identified by ABC’s court reporting to be Louis, uh, Gaebler. Uh, you know, what can I say? It, on one hand, play stupid games, get stupid prizes, uh, F around and find out. But also, um, these are two incredibly young people.

[00:01:02] Jenn Gile: Uh, one of, has a, a history of drug abuse and employment problems. The other has gotten involved in some pretty nasty neo-Nazi stuff. Uh, honestly, as a parent, I hate to see two young men having gone down this path. I hope that whatever comes next for them, uh, gives them an opportunity to decide to do something different with their lives.

[00:01:28] Jenn Gile: They’re young and they have a lot of life ahead of them, hopefully, and I hope they’ve learned from this

[00:01:34] Paul McCarty: You, like you and I are just so different in this regard. Like, we’re both parents, right? And so I think that’s an important thing to… But I am just so, like I have no sympathy for them. They’re

[00:01:47] Jenn Gile: drug addicts- Oh, don’t get me wrong.

[00:01:48] Jenn Gile: I have zero sympathy for them. Okay. What they did was incredibly wrong. But these- But listen, th- … are also, like, it’s sad to see … young men This is not your, like, hardened criminal, uh, life of crime kind of thing. Like, these are, as we’ve been talking about for several months, a couple of, like, kind of dumb kids.

[00:02:08] Paul McCarty: Yeah, and I think that that’s gonna be the theme running through today’s show, which is just dumb kids. They just did a bunch of dumb stuff, which we knew, uh, we were calling out before they got arrested. But, um, I think, uh, one take on that last part or that first part there before we move into the, the heart of today’s conversation about these guys, is that, listen, I understand they’re at the beginning of their, their lives, but they also come from what appear to be relatively well off parents.

[00:02:37] Paul McCarty: They seem like mostly useless drifter type people. Like, listen, I was a, I was a 20-year-old man, right, that was trying to figure out, you know, where I was. And you know what I did? Is I found, I, I found a passion, and I followed it, and I became successful, right? So I don’t have… I don’t, I don’t, I don’t know.

[00:02:56] Paul McCarty: I’m, maybe I’m giving-

[00:02:58] Jenn Gile: Well, no, I don’t disagree with you, ‘cause s- you know, I was reading, uh, Brian’s Kreb- Brian Krebs’ article in detail, and I found Ruben Thomson’s general attitude about the job industry to be, on one hand, understandable, 'cause getting into cybersecurity is not easy. But on the other, he acted like he didn’t see an alternative, and I just, I have a tough time with that.

[00:03:29] Jenn Gile: You know, I know a lot of people who work hard to get into cybersecurity who have the same, uh, barriers that he may have had. Uh, you know, they talk in the article about, you know, if you don’t have experience, employers won’t look at you. There are a lot of ways to get experience.

[00:03:49] Paul McCarty: Well, you know, bad people like to latch on legitimate arguments like that to make, to validate why they did what they did.

[00:03:58] Paul McCarty: And let me just start out by saying something super crazy, which is Jeffrey Dahmer, before he killed his first person, k- you know, was just a 20-year-old man who hadn’t done anything, right? And, you know, the innate evil within him, and these two guys, I got, I got no sympathy that, well, I know you, neither one of us has sympathy for them.

[00:04:17] Paul McCarty: But I, um, I hope they throw the book at them. Um, not only do I hope they throw the book at them, um, th- these two young kids are just gonna, even in Australian prison, because both of them are white supremacists. That’s the other thing you have, like, they both… One of them, Casper, is more out there. But you look at some of the things that, that old mate Ruben has said.

[00:04:38] Paul McCarty: He comes from South Africa, and he comes from a, he comes from a, I don’t think he comes from a Boer background, but I think he comes from an Anglo background in South Africa, and is very, um, you know, entrenched in that kind of white supremacist, Anglo nationalistic, and there’s

[00:04:55] Jenn Gile: some out- Yeah, they’ve said some pretty nasty things.

[00:04:58] Jenn Gile: It’s-

[00:04:58] Paul McCarty: There’s a, there’s, there’s this growing movement, and I don’t wanna give it too much play here, but there’s this growing movement called remigration, right? Which is just a fancy word for racist white supremacist nationalists, and there is some overlap. Um, last night a, um, a journalist was pinging me some stuff about some of the remigration things happening here.

[00:05:17] Paul McCarty: And there’s a connection between that and some of these, like, South African folks. Um, anyhow, more to be discussed later on. Let’s jump into the heart of this, Jen. Let’s get her on.

[00:05:26] Jenn Gile: Well, so where do you wanna start with it? Because, uh, there’s plenty to discuss from the Krebs article, from the, uh, AFP, uh, press release.

[00:05:37] Jenn Gile: I know you have been, uh, talking to people behind the scenes for- multiple months, I wanna say. Uh, so you, you know, kinda- Yeah … knew this was coming. Um, what do you wanna discuss?

[00:05:53] Paul McCarty: Yeah, I mean, I like, uh, you know, I was privy to some inside baseball. Um, you know, and I don’t wanna go into a lot of details 'cause I don’t wanna, you know, I don’t wanna be part of- Yeah, it’s not necessary

[00:06:03] Paul McCarty: inside baseball in the future. Yeah, I, you know, I want… But, but the reality is that, um, I had some intel that, you know, one of these people was perhaps in my country. Um, and um, you know, some meetings took place because of that. But, um, I think the first thing I wanna say, start out by saying is that, listen, we were right.

[00:06:24] Paul McCarty: We called it, right? Like, basically Team PCP is one guy, Ruben Thomson, right? 21 year old from Cottesloe, outside of Perth. It’s a, it’s a well-to-do suburb in Perth. Um, he is South African, so the, all the intel about the South African part is true. And, you know, like, this is what happens. You said it earlier, F around and find out, right?

[00:06:45] Paul McCarty: Like, they, they prodigious posting on Twitter and Telegram and all kinds of other places. Didn’t delete it.

[00:06:51] Jenn Gile: Their OPSEC was terrible. Their

[00:06:53] Paul McCarty: OPSEC is terrible. Reusing the same username and the same stupid password. Like, Krebs just like, the Krebs article is just brutal in its efficient- Beautiful, yeah … oh my God, it’s just like brutal in its efficient tear-down of how stupid these…

[00:07:11] Paul McCarty: I can’t say any cuss words, but I really wanna say that dip word. Um, they’re just, uh, just morons. Yeah. Right? And I think it’s hard for us to reconcile the fact that they are so stupid and made so many mistakes with the fact that their attacks in March and April and May were pretty complicated. I mean, and yes, they were borrowing heavily on the original Shai Hulud threat actors and, you know, borrowing from the ecosystem.

[00:07:36] Paul McCarty: But you know, it was effective because, you know, it was, it, it attacked a place where not a lot of people really kinda understood what was kind of happening. And we talk about that in that, that interview that we did with, with Akito and Saka and all those guys. The fact is that we all, many of us use GitHub Actions every day, or the equivalent, just to be clear.

[00:07:54] Paul McCarty: Mm-hmm. And there’s just a lot going on there that we don’t really kind of talk about. There’s just a lot of containers and stuff going on there, and they took a, they took advantage of that, right? And they were very effective. They didn’t, they weren’t able to actually make any money. My understanding is they made about $90,000, like, at just-

[00:08:10] Jenn Gile: Well, the, the Krebs article says that Thomson made, like, 20K.

[00:08:15] Jenn Gile: So-

[00:08:16] Paul McCarty: yeah …

[00:08:17] Jenn Gile: yeah. I mean, not sophisticated. Uh, I think this is a great example of how an LLM can get an unsophisticated bad actor further along than they would’ve been, but it can’t make them… I mean, let’s go back to our, uh, terminology from North Korea. You know, it doesn’t build a go-to-market for them. It doesn’t build a business for them.

[00:08:44] Jenn Gile: You know, they- Yeah … you have to know, uh, how to do targeting and how to take advantage of the data that you get ahold of. And so the good news out of this is they’re not- You know, terribly smart about what they did collect. Um, let’s just hope this is the last we’ve seen of this.

[00:09:04] Paul McCarty: Well, yeah, and let’s talk about that for a second.

[00:09:06] Paul McCarty: Um, my understanding is that there’s a lot more to come. Now, and, and I, that, when… So, what does that mean?

[00:09:15] Jenn Gile: You mean around the, um-

[00:09:19] Paul McCarty: Law- law enforcement …

[00:09:20] Jenn Gile: not 100% coming, but more, more people getting in trouble or outed.

[00:09:23] Paul McCarty: Law enforcement activity. Yes. And here’s the thing is that, uh, you know, aside from exploiters, who still is in the wind, um, TeamPCP’s been wrapped up.

[00:09:32] Paul McCarty: So what is there more to do about that, right? Like, I called it, you know, this, basically I was saying TeamPCP was, like, one guy, maybe a second helper, and that’s exactly what we have here. Um, you know, are there some other people ancillary around them? Of course, yeah. Like, and, and KernelStub right now is out there just, you know, talking about how they turned themselves in and all this other shizzle.

[00:09:50] Paul McCarty: But, um, the reality is it was relatively small- There is a lot of trash talking

[00:09:53] Jenn Gile: online right now …

[00:09:54] Paul McCarty: yeah. Oh my God, so many people like, you know, “Oh, I was in the know,” and oh, just got some of the most toxic personas on Twitter, but, um, which is the right place to be toxic. Um, but the point I’m driving at, uh, here is, is an important one, which is if there’s more to come, and T- TeamPCP has effectively been wrapped up with a few threads hanging out there, what are we…

[00:10:15] Paul McCarty: W- what’s coming? Mm. And m- my expectation is that there is gonna be movement against Lapsus$ and ShinyHunters and some of these other groups because there’s enough overlap between some of these groups where, um, and I, I, I wanna hope, mate, Francois, you know I’m, I’m talking about you, buddy. I’m hoping that something that w- Francois, Francois and I worked on, um, ends up, um, doing some good out there.

[00:10:42] Paul McCarty: But, um, uh, you know, I think the reality is that, um, there are gonna be more arrests, there are gonna be another crews, and, um, there’s gonna be kind of this domino effect. Sorry to use these cliche terms, but there’s gonna be a domino effect here where, like, once you get that much data from some… Because they’ve already pulled, like, I heard in one of the things 100 terabytes already off of old mate Ruben’s machine.

[00:11:06] Paul McCarty: Um, and you know, as everybody knows, they stole, uh, just a ton, absolute ton of credentials. So, you know, just a lot of, there’s a lot of gold there. And based on the rest of their OPSEC, I’m gonna guess that all this data was just sitting on their hard drives. Which the AFP now has, uh… And big shout-out, by the way, to AFP for- Not that they get back to people when they turn…

[00:11:30] Paul McCarty: Anyhow, but, um, the, that aside, a big shout-out to AFP for working with the FBI to, to do this takedown. Um, so good on 'em.

[00:11:37] Jenn Gile: Yeah. Good news today. Okay, let’s talk about-

[00:11:42] Paul McCarty: Today’s a good day,

[00:11:43] Jenn Gile: Jen.

[00:11:43] Paul McCarty: Today’s a good day. It’s a- Today’s a good- It’s a good- We, you and I have been talking about this day, like, we literally have been talking about this happening for a while now.

[00:11:50] Paul McCarty: Like, we knew it was happening. Mm-hmm. We just were waiting for the machinations to go through, and, and here we are, it’s happened. TeamPCP has, has effectively been taken down. That’s awesome.

[00:11:59] Jenn Gile: Yeah, very happy about it.

PolinRider persistence mechanisms

[00:11:59] Jenn Gile: Um, now let’s talk about our favorite subject. Uh, and I only say that because I think we do talk about this just about every podcast, but that’s because we’re always finding new things.

[00:12:14] Jenn Gile: So this is what’s going on with PolinRider. Um, we are preparing to do a talk in, what, a week, week and a half. Um, and so we’ve been preparing for that and doing some extra hunts, and found some interesting new things. Uh, some of it is more like- Reinforcing that it is bigger than what the data was initially showing.

[00:12:40] Jenn Gile: Some of it is showing it went back further than what the data initially showed. Um, we published a blog, I’ll share the, um, link in the comments, that, uh, goes through a pretty interesting case study of a person who got, uh, I won’t even say reinfected 'cause they never cleaned out the infection to begin with.

[00:13:04] Jenn Gile: Yeah. But they got infected, they thought they cleared it out. Uh, it has been pushed into their packages. So, um, maybe, maybe let’s start there, and then you can open up into the broader hunt that you’ve been doing.

[00:13:18] Paul McCarty: Yeah, I mean, at the heart of this is the fact that you just have a lot of developers, um, that have been compromised over the last couple of years.

[00:13:24] Paul McCarty: Contagious interview from DPRK has been going on since 2023. A lot of people are compromised. The problem is that what we didn’t really kind of talk about as much as we probably should have, is the fact that the DPRK maintained persistence on these developers’ machines. Um, and that is rearing its head now as all these compromised GitHub users…

[00:13:45] Paul McCarty: They’re compromised on their local machines. Their GitHub accounts aren’t necessarily, um, uh, compromised, but they’re compromised on their local machines, so the persistence is happening on their local machine. And, uh, what we’re seeing now, we, and we talked about this a couple episodes ago with, with Go.

[00:13:59] Paul McCarty: We- every day we see a new smattering of PolinRider in Go packages, because Go doesn’t have a- an additional publish step like NPM or PyPi does. But we are now seeing PolinRider in PyPi, we’re seeing it in NPM, we’re seeing it in VS Code, we’re seeing it in other places. As these developers, you know, go about their daily business and they go to deploy a new NPM package or new PyPi package or whatever, the PolinRider malware slides through in- inside of that new thing.

[00:14:28] Paul McCarty: So in this particular case, the Fetch page assets in HTML, the Gutenberg maintainer, um, Diogo was compromised and, you know, NPM took down version whatever dot nine of, of, um, Fetch page assets. But then immediately he published dot 10, dot 11, dot 12, dot 13. These are all legitimate pushes by the real, um… Or actually in those cases, Jen, I think that might have been DPRK doing

[00:14:55] Jenn Gile: those pushes.

[00:14:55] Jenn Gile: No, they’re all… Well, okay, let’s rewind a little bit. Oh, the-

[00:14:58] Paul McCarty: yeah.

[00:14:59] Jenn Gile: So Diogo is a, a legitimate developer who got compromised. Uh, we don’t know specifically how he did, but probably given his, um, profile of like an independent developer, it was probably through contagious interview. Um, it looks like it happened maybe around January of this year.

[00:15:21] Jenn Gile: And, um- The way that this particular piece of malware works is, yeah, it’s on your machine, but then it looks for places that it can inject its payload and then pushes them to your repos. And so that’s what happened, is through his normal CI processes, uh, infected files were pushed into all of his repos.

[00:15:46] Jenn Gile: And then because two of those re- repos serve, um, as source code for two corresponding npm projects, when he pushed updates to those npm projects, new versions, the malware came along for the ride. And, uh, that malware was discovered a few months ago. It got taken down relatively quickly. Um, he went through some remediation steps.

[00:16:11] Jenn Gile: We can see evidence of that where he deleted the files that had the payloads in it, but he only did a partial job. He didn’t delete the vscode-task.json files that were triggering those payloads. And we can assume he also, uh, didn’t properly probably clean his machine and we can look through his repos and we can still see evidence of infection in his repos.

[00:16:35] Jenn Gile: And whether he continued to push new versions or the threat actor, I would say it’s probably him. He probably, you know, was making updates to his packages. We can see this series of, you know, updates coming out over the last couple months where he pushed a new version 'cause he wanted to, you know, have a non-malicious version.

[00:16:55] Jenn Gile: And then the threat actor was able to push a new, uh, payload onto his machine and that is through the, the wrap that is undoubtedly on his machine, which then trickled its way back into his packages. And so May, I think, is when those original poisoned packages were published. They’ve each had a few versions come out since.

[00:17:21] Jenn Gile: They are all malicious. Uh, and I think the thing that surprised us was that nobody has caught this. These, this was a known compromised developer. Uh, two known compromised packages. Not only did we not catch it, um, you know, we’ll own our own thing here. NPM didn’t catch it, which certainly I would’ve hoped that they would’ve since he Should already be on their radar, but as you talk about in your blog, they’re focused on the package as the important data point, not the individual.

[00:18:02] Jenn Gile: None of the other scanners seem to have picked it up either, so he has had this persistent infection for several months that has had evolved payloads, so no fun for him.

[00:18:13] Paul McCarty: Yeah. I, and I think the timeline is important, because each victim is, is a little bit different. Because what happens is the infection starts on your local machine via, um, a malicious Git repo that gets…

[00:18:27] Paul McCarty: The payload gets run from VS- typically from VS Code using the task function. Sometimes there’s other alternative ways. There’s, sometimes there’s a Git hook, and other times you, you run the app and it, when you run the app, it actually runs some system commands. There’s a number of ways, but most of the time it’s VS Codes.

[00:18:41] Paul McCarty: So you’re compromised on your machine, and then what happens is that allows North Korean threat actors to manipulate files on your machine. They have access to your disk, and what they do is they go and look for all the Git repos that you’ve got, which you said earlier, and they find ones that m- match what they need, and they push these payloads in.

[00:18:59] Paul McCarty: Now, the second part, this is where things sometimes change. If they have, if North Korea has access to your credentials, because when the info stealer that was part of that RAT and part of that kill chain, when the info stealer runs, if they get access to your Git, um, account via a PAT or some other function, then what they do is they will then push.

[00:19:18] Paul McCarty: And so in Diogo’s case, there were pushes that our system identifies as non-human. So basically what happened is DPRK orchestrated changes on his local disk to files that were inside of the Git repo. It then also orchestrated the push of those out, you know, basically overwrite a commit and then push it out to GitHub.

[00:19:39] Paul McCarty: So those two things both were automated by DPRK. The third thing, which was not automated, which is the publish of the NPM package, those were always Diogo himself doing those as part of legitimate work. He just didn’t realize that his GitHub repo, repo that was building the NPM package had this, you know, persistent payload sitting on top of it.

[00:20:01] Paul McCarty: And DPRK pushed three additional payloads into the Git repos, so the last one wasn’t that long ago. It was just a few days… Well, about a week ago now, but… And that last one is NullReceiver. It’s the latest version. It’s got brand new campaign marker. It’s the f- best, and, and that’s the problem with this, is that when DPRK has access to your machine and can, and has a RAT running there, they can keep pushing new, better payloads- It means

[00:20:24] Jenn Gile: they’re helping you out.

[00:20:25] Jenn Gile: They’re giving you updates, right?

[00:20:28] Paul McCarty: They’re giving you the wrong updates. Yeah

[00:20:29] Jenn Gile: Wrong updates. Um-

[00:20:31] Paul McCarty: You wanna pin their old, you wanna pin their old version of their own malware.

[00:20:35] Jenn Gile: We’ve been mapping, uh, their persistence mechanisms, and there’s at least four separate persistence mechanisms related to this campaign.

[00:20:46] Jenn Gile: Some of it’s in the original kill chain, some of it’s PolinRider specific, but there is a new one, um, that somebody in the community surfaced maybe a week or two ago, where they have now added a step in their kill chain where they overwrite the NPM CLI with a malicious version of the CLI. That’s a particularly nasty one.

[00:21:09] Jenn Gile: So even, even if you clear off everything else that we’ve been talking about for months, this little malicious npm CLI, the next time you fire up npm, will say, “Reinstall malware?” And it just kicks off the whole thing again.

[00:21:26] Paul McCarty: If you, if you find the, the Python or the JavaScript persistence, the RAT, and you kill that, and you find where it’s starting from, from a bashrc file or an npmrc file or wherever it is, if you kill that, if you get it out of there, if, you know, if you go and look and find all the payloads in all your Git repos and get rid of those, and actually remove them from your Git index, 'cause just pushing a new version of it doesn’t mean that the payload’s gone, it just means you’ve got a new version that doesn’t have the payload.

[00:21:52] Paul McCarty: If you do all those things alone, but you don’t uninstall or delete npm, you’re gonna get reinfected because the next time you run npm, it’s… So basically the normal size of npm, which by the way is just a… npm CLI is just basically a bunch of like, um, symlinks to different JavaScript files, most of which end up in a, uh, in a CLI folder inside the npm.

[00:22:15] Paul McCarty: Anyhow, it’s crazy. Why would you do that? But it’s JavaScript. Um, they overwrite that 200 byte file with a file that ends up being something like 1000K or- It’s big. Yeah, I think it’s big … yeah, I think it’s, I think it’s 1100K or something like that. Um, but, and, and some p- people, you know, we didn’t even do this, some people out there in the open, in the wild, have created tests, um, for some of this stuff, so, and, and we’ve pulled that into our blog and also shouted out to them too as well.

[00:22:40] Paul McCarty: So there’s some really simple things you can do to look at the size of your npm file, for example. Um, just make sure you’re following the symlinks. So if not, then not gonna work.

[00:22:50] Jenn Gile: Yeah. The other thing that you said you’ve been observing is, um, so there’s two kinds of files that this malware will create on your machine, or modify on your machine.

[00:23:01] Jenn Gile: We’ve talked extensively about the task.json files. We are still seeing, um, lots of ones that are config files, JavaScript or TypeScript config files. And Paul, you said that initially they tended to save those in index, but now you are seeing them all over the place, that they’re just spread and it’s not, you know, three or four different types of files, it’s really just any kind of config.

[00:23:29] Jenn Gile: Yeah. Talk a little bit more about what you’ve been observing.

[00:23:33] Paul McCarty: Yeah, good call out. Um, so in the original version of PolinRider from, from March of 2026, um, basically what happens is in that, in that part of the kill chain where their malware is going and looking for JavaScript files to write into, it was only looking for five or six files, vite.config.,

[00:23:52] Paul McCarty: you know, js and, and You know, a Babel dot, you know, config.json, and just a very small number. And then that number grew over the next couple months and, you know, they were looking for like 15 or 16 different files, and if they’d find that, they would just append their payload on the end of it. Well, now- Yeah

[00:24:09] Paul McCarty: they’re just looking for any JavaScript file. Any, and w- what they’re also doing, Jen, is they, is they’re looking for files that are actually getting used as part of the execution order for that particular project. So that’s what’s smart about it is they, they don’t just go and find some like random- Mm

[00:24:25] Paul McCarty: JavaScript file. They basically look at the code and really briefly take a look at kinda how the, how the call, um, process works, and then they find a, a JavaScript file that’s actually gonna get called, and they drop it into there. So we’re

[00:24:37] Jenn Gile: now seeing- Oh, that’s that reachability.

[00:24:38] Paul McCarty: Yeah, exact- It was really, really well, I…

[00:24:40] Paul McCarty: It’s very simplistic- … reacha- reachability. But, that’s funny. Um, but, uh, so we’re seeing it now in all kinds of stuff. So basically this is one of the things, this is why our hunt keeps growing, is that, you know, we had that original five or six files they were looking for, then we had like the 10 or eight or whatever, and then it was grew and grew.

[00:24:59] Paul McCarty: And now we just look for any types, types, any… Here’s the extensions you wanna look for: .js, obvious, um, excuse me, .ts, TypeScript, also probably should be o- obvious. Then all the minified and the, the, the, um, uh, the ESM and CommonJS files, CJS, MJS, and that whole kind of family. So there’s like five or six extensions you wanna look for, um, which means that you’re searching now is gonna be, you know, longer.

[00:25:26] Paul McCarty: It’s gonna be more, it’s gonna take more time because you’re looking through a lot more files, but you know, that’s what you gotta do. And when we’re doing that now in GitHub out there forward hunting, we’re just finding a lot more files. I pushed like, I don’t know, 1,200 or 1,400 new GitHub repos to OSM just yesterday, one day.

[00:25:42] Jenn Gile: Um, you said something that gives me an opportunity to get up on my soapbox, and I know you’re gonna join me up on it. Um, because this takes so much time, uh, this is not just about, like, cleaning your own stuff and worrying about yourself. For every minute, hour, day that you’re going through incident response, if you have public repos, if you’re collaborating with anyone, uh, the infection is spreading to your network.

[00:26:14] Jenn Gile: And I know that disclosures suck. Nobody likes to do that. But if you’ve found that you’ve been infected, uh, please, please, you know, disclose. Tell people in your network that you know are collaborating- Mm … not just because it’s the right thing to do for the community, but if you clean out all signs of infection and then you’re still collaborating with people who are infected, you’re just gonna get reinfected.

[00:26:41] Jenn Gile: So if you don’t give them the opportunity to look for signs of compromise and address it, you’re hurting yourself in addition to them.

[00:26:51] Paul McCarty: 100- oh my God, great call-out. Um, and we are s- we are genuinely seeing that. So people, they, they say, “Oh, there were…” Some, you know, like for example, I’m automating disclosures now into open source projects that we find PolinRider in.

[00:27:04] Paul McCarty: We’ll basically have an automation thing that goes out there and drops an issue into the GitHub issues for that particular project. What’ll happen is they’ll see that, then they’ll remove it from the GitHub repo, and they won’t say anything. They’ll close the issue, and they won’t say anything, right? But then the problem is that somebody inside, one of their contributors or maintainers, or sometimes multiple, uh, will still be infected on their laptops, and the whole thing will just come back.

[00:27:26] Paul McCarty: And we’ve now seen that with some of these, these open source projects where it started out as one or two people inside of the contributor group had it, and now they’re all infected. It’s like COVID, except you can’t build up an immunity. You can just get it immediately again, right? So, um, to your point, I think we need to do a lot better at just saying, "Hey, listen, I got hacked.

[00:27:45] Paul McCarty: Um, and here’s what, you know, here’s what we did. We suggest you do the same thing. Here’s the things to look for." And reference our, that great, um, blog post that you put together, PolinRider, for, for developers.

[00:27:56] Jenn Gile: Yeah. Thank you. I’ll drop that link in the chat. I put together a little incident response remediation guide.

[00:28:04] Jenn Gile: Um- You know, this conversation, um… Hold on, I can type and talk at the same time, I swear. She’s done it once. Um, this reminds me of, you know, the whole there’s two kinds of companies, those that have been compromised and those that don’t know they’ve been compromised. Right. I think we’re, you know, this is, this is a similar thing.

[00:28:27] Jenn Gile: Um, this is spreading widely. It’s evolving rapidly. Um, the signals are constantly changing. You know, we’re constantly updating our own internal detections because what was reliable weeks or months ago is no longer being used or not being used as widespread. Um, so yeah, I guess this is a plug for having some intel on PolinRider so you know what to look for, but start with the blog that I wrote because it’ll at least give you some places to look

[00:29:06] Paul McCarty: Excellent.

[00:29:07] Paul McCarty: Excellent advice. I have nothing to

[00:29:09] Jenn Gile: add. Nothing to add. Don’t know what to add. Okay, let’s wrap it there.

Closing

[00:29:15] Paul McCarty: Sure.

[00:29:15] Jenn Gile: Sounds good. As a, a heads-up to our dedicated listeners, of which there are some, which we love, um, we are gonna take a break next week for a little- Yep … much needed, uh, vacation time/family time on each side, and then we’re gonna figure out when, how, where to record an episode while we are in Strasbourg, um, coming up, uh, in the first week of S- or I guess second week of September.

[00:29:47] Jenn Gile: So very much looking forward to another, uh, live from the conference, Jen and Paul talking about what we’ve, uh, been experiencing, learning, et cetera.

[00:29:57] Paul McCarty: And hopefully I’m not sick this time. Um- You’re not gonna be

[00:30:00] Jenn Gile: sick this time. You’re gonna be so

[00:30:01] Paul McCarty: healthy.

[00:30:02] Jenn Gile: No.

[00:30:02] Paul McCarty: Um, my, my immune system’s all jacked up now. Um, yeah, just to kinda double click on that, we will be in Europe, uh, September 6 to 11.

[00:30:11] Paul McCarty: Um, uh, and I’m actually- 7 to

[00:30:13] Jenn Gile: 10 If you’re in Australia, it’s the 6th through the 11th. Yeah. Oh, sorry, the conference-

[00:30:20] Paul McCarty: is the

[00:30:21] Jenn Gile: 7th. Yeah, I’m, I’m also gonna be there. I’m gonna be there September 11th too as well. I’m actually talking at, uh, I’m actually, sorry, I’m giving training on GitHub CTI stuff at, uh, Frankfurt BSides on the 11th.

[00:30:32] Paul McCarty: I’m having dinner with some friends the night before, so I’m really looking forward to this. Um, so yeah, if you’re gonna be in Frankfurt or Strasbourg, um, for whatever reason let us know. We have a lot of users in Europe, so we have a disproportionate number of OSM users in Europe, so come out and say hi.

[00:30:51] Jenn Gile: On that note, have a good one.

[00:30:53] Paul McCarty: Yeah, thanks for listening. We really appreciate it.