BLOG
The OpenSourceMalware Show #20
Mini Shai-Hulud npm resurgence, OpenSourceMalware one-year anniversary, and Underground Economy conference Q&A on DPRK myths and GitHub security gaps
By cb482791-4ef1-4762-96ad-b0ca4bdd538e ·
The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.
This week we talked about:
Mini Shai-Hulud payload resurfaces on npm. A payload from May’s Mini Shai-Hulud campaign against AntV reappeared in four packages published within the same hour on September 7th, sitting undetected for 111 days despite npm’s publish-time scanning.
Q&A from the Underground Economy conference. Reporting live from Team Cymru’s conference in Strasbourg, Jenn and Paul answer the questions they fielded all week: whether DPRK and Russia collaborate on supply chain attacks, why malicious open source rarely targets specific countries, whether North Korea needs AI to close a skills gap, why GitHub allows git history to be rewritten and hasn’t done more to stop PolinRider, and what developers can realistically do to protect themselves, since PolinRider’s payload runs regardless of what language a repo is written in.
We also marked OpenSourceMalware’s first anniversary, now tracking close to 200,000 verified threats and over 100,000 IOCs.
Resources
(blog) Shai-Hulud Rises From the Dead after 111 days
[00:00:00] Jenn Gile: Hello. It is Wednesday, September 9th. Paul and I are live from Strasbourg, France. Uh, it’s 2:35 in the afternoon for us, but I think our bodies are in vastly different time zones still. Um, but we’ve been having a great week at the Underground Economy, Economy Conference, which Team Cymru puts on. We’ll talk about that a little bit more.
[00:00:24] Jenn Gile: Uh, Paul, why don’t we start first with the news? And what I will say is like pleasantly surprised, it’s been a quiet couple of weeks in, uh, malicious open source, right?
[00:00:35] Paul McCarty: Yeah. I mean, I was saying this earlier, like I, I think it’s quiet is, is relative. It’s quiet in the sense there haven’t been any big, you know, attacks, right?
[00:00:42] Paul McCarty: Team PCP is, um, be- behind bars. But you know, North Korea and everybody else is humming along and, and you know, uh, they’re, uh… We’re averaging just over Um, it’s at least 115 malicious GitHub DPRK-related Contagious Interview, uh, GitHub repositories a day. Over 100, um, roughly 115. So the number of malicious things is increasing, so, uh, it’s hard for me to say-
[00:01:13] Jenn Gile: Yeah.
[00:01:14] Jenn Gile: Yeah, you’re right. Uh- Mm-hmm … quiet is certainly relative. I was looking at the number of total verified threats in our database, and we are getting very close to 200,000, and that has been kind of, uh, you know, certainly steadily increasing over the last year. But, uh, we’ve seen a big increase in recent weeks.
[00:01:34] Jenn Gile: Um, it’s not on our list, but hey, happy birthday open source malware. Um- That’s right … for people who haven’t followed our LinkedIn- That’s right … uh, we’re celebrating our one-year birthday since, uh, Paul, uh, got frustrated and DIY’d. So maybe before we get into the regular, uh, agenda, how you feeling after a year of doing this?
[00:01:58] Paul McCarty: I… You know, it’s pretty amazing. Like, you know, you and I at conferences over the last few months, you know, people routinely come up to us and say, you know, they, they know us from the podcast here, they, they use the platform. But particularly at this conference, a lot of the people we’ve talked to are pulling our data, um, our free APIs, and that is…
[00:02:18] Paul McCarty: It just really fills me with a lot of pride, um, that, you know, the, the, the pain that I saw, you know, it, you know, is shared with other people too as well. And so that makes the data that we provide, you know, valuable to a lot of other people too. So I, I just… It makes me eve- And I know in the Bible, pride is one of the seven deadly sins, but screw that noise.
[00:02:40] Paul McCarty: I’m, I’m very proud of, of building this thing and how it’s taken off. Um, so that’s pretty cool.
[00:02:46] Jenn Gile: Yeah, I think you should be proud. Um, you and I both love open source. It feels good to do something, uh, that helps the community, both the open source community and the security community. So yeah, uh, as much as I think we don’t wanna see hundreds of thousands of threats in our database, like, that sucks 'cause that means there are threats out there.
[00:03:07] Jenn Gile: Also, I’ve got a bit of pride that we’re, you know, a year in and have that much valuable data that is helping the community. So yeah, it feels pretty good.
[00:03:17] Paul McCarty: Yeah. And I wanna mention too as well, we, we’ve got over 100,000 IOCs as well as part of the, the new stuff. So, you know, um, yeah. It’s awesome.
[00:03:27] Jenn Gile: Yeah. Okay.
A Mini Shai-Hulud payload resurfaces on npm
[00:03:28] Jenn Gile: So, uh, the one piece of news that I thought was notable over the last couple of weeks since we recorded the last time, uh, over at Aikido, Charlie published a blog about four packages that were, um, published on September 7th, uh, all within the same hour from the same NPM account. Um, the story here is not Oh, no, these are scary.
[00:03:54] Jenn Gile: Something terrible is happening. The story is actually that they bear the many Shai Hulud, uh, malware from back in May, uh, the variant that went through AntV. And, um, the way that he found them is the hash matched, which as you and I have talked a lot, you know, often the hashes are not the best way to find things, but in this case, you know, because it stayed static, uh, he found it that way.
[00:04:20] Jenn Gile: Now, uh, is this malware dangerous? No, 'cause all the C2 infrastructure is down at this point. Um, but it’s pretty interesting to see somebody had this stuff hanging out in their repo presumably for, what is that? May, May, June, July, August, you know, four to five months, and, uh, it’s rearing its ugly head again.
[00:04:43] Jenn Gile: Um, the comment that he made, which I think is a great point, is this was easy to detect, um, if pre-publication scanning is happening in npm as we’ve been told it is. This is like the lowest of the low-hanging fruit. Um-
[00:05:01] Paul McCarty: Yeah …
[00:05:01] Jenn Gile: so yeah.
[00:05:02] Paul McCarty: Let me-
[00:05:02] Jenn Gile: It’s a little
[00:05:03] Paul McCarty: disappointing … let me, let me say this a little bit differently and a little bit spicier.
[00:05:06] Paul McCarty: Hey, npm- I
[00:05:08] Jenn Gile: thought I was being pretty spicy.
[00:05:10] Paul McCarty: Well, I mean, for Jen, that was pretty spicy, but- Okay … for Paul, um, hey, npm, if you are actually scanning for malware in your registry, please present evidence of said scanning 'cause we don’t see it.
[00:05:26] Jenn Gile: Yeah, highly doubtful. Um, let’s see. Is there anything else interesting to say on this?
[00:05:33] Jenn Gile: Uh, yeah, I mean, essentially what we think, what Charlie thinks happens is this was hanging out in somebody’s pipeline. You know, they pushed some updates, and, uh, as we have seen with PolinRider and other campaigns, they accidentally pulled the malware along with it. So, uh, this is not like a new wave of the worm is coming out.
[00:05:53] Jenn Gile: That’s not what he’s saying. That’s not what we’re saying. Uh, but it’s more a testament to these things linger
[00:06:02] Paul McCarty: Well, and source code has this weird way of, you know, getting itself back into, like old source code or, or, or, um, isolated or orphaned source code has this weird way of working itself back into main.
[00:06:14] Paul McCarty: And I was just thinking a second ago, 'cause, 'cause you and I were like speculating before the, the thing, the, the podcast about how it got broke free. And just as we were talking about it, just as we were recording, I thought, you know, I’ve seen this before with, um, with DPRK stuff where it’ll get stuck in a branch.
[00:06:31] Paul McCarty: Basically what happens is it gets orphaned in a branch, not orphaned, but it gets kind of stuck in amber in a branch. And then what happens is months and months and months later, somebody does a bunch of merging, um, you know, and, and alignment work, and then suddenly something is in main, um, and out it goes.
[00:06:50] Paul McCarty: And that’s probably-
[00:06:50] Jenn Gile: Yeah, I mean, these projects look pretty unrelated. Like two are clearly related, but the other two seem unrelated. Uh, this reads to me like somebody went in and did some cleanup and, uh, made an oops.
[00:07:05] Paul McCarty: Didn’t even realize what happened. Yeah. Um, I, I think it’s also evidence of the fact that, you know, like this stuff has consequences even after…
[00:07:14] Paul McCarty: 'Cause you said, you know, the CTU infrastructure’s down, the domain doesn’t even resolve anymore. But, um- That doesn’t mean that you didn’t just have malware running your machine, right? Like, yeah, it didn’t… It can’t talk, and I can’t remember the order of execution here, but I think this is the exfil stage.
[00:07:28] Paul McCarty: So like, you know, it still ran on your machine, right? Which is not good. Um, it just didn’t exfil to TW-club or whatever the hell it is, um, the, the URL. So, um, I guess the point I’m trying to make is that the malware still ran, you know?
[00:07:44] Jenn Gile: Yeah, that’s fair. Uh, the malware can still run. It’s just whether or not the exfil is out there.
[00:07:49] Jenn Gile: So I’m sharing, uh, the blog in case anybody wants to check it out, uh, over on Aikido. But yeah, again, this is not like an emergency here. It’s just an interesting thing that happened. So flipping over to the conference, um, uh, been pleasantly surprised, uh, to meet people who are familiar with the platform, who’ve seen us, uh, around the, uh, interweb universe.
Live from the Underground Economy conference
[00:08:14] Jenn Gile: So, uh, Underground Economy is a CTI, so that’s Cyber Threat Intelligence and Threat Hunting conference. So these are the more forward hunting, looking at what’s out there. We’re meeting a lot of people who are in law enforcement, who work for nation-state certs, um, but also lots of people who are doing incident response, SOC, a huge range of people.
[00:08:35] Jenn Gile: Um, it’s a fairly small conference, seven hundred or so people. Um, but we went ahead and, uh, took down some of the questions, top questions that we’ve gotten from this group this week, because it kind of gives you a little bit of a, like a look into, uh, the questions that this group has about malicious open source and what we’re doing and these threat actors.
[00:09:00] Jenn Gile: Um, so yeah, that’s what we thought would be kind of interesting to share for the rest of the episode since, again, fortunately, it’s been a, a quiet news cycle. So in, uh… And I guess I should say, we gave a talk yesterday on PolinRider. That was our, um, you know, privilege to be here for that. So we were educating the community about, uh, DPRK attacking developers.
[00:09:25] Jenn Gile: Uh, this is an area that this community is not as familiar with, so it was a really great opportunity for us. Okay. Um, let’s see here. In no particular order, uh, we had somebody ask us if, um, we’re seeing evidence of collaboration between, uh, North Korean and Russian state threat actors. And I thought that was an interesting question.
Are North Korea and Russia collaborating on supply chain attacks
[00:09:50] Jenn Gile: Um, the way that the person phrased it was, you know, because these are countries that are already collaborating on different levels, you know, are they collaborating in the software supply chain attack space? Um, short answer, no, we’re not seeing any evidence. Um, Paul, maybe you wanna talk a bit, uh, more on the long answer of why you think it’s probably not happening.
[00:10:12] Paul McCarty: Yeah, I mean, I think, I mean, I think that there are definitely North Korean, you know, DPRK, um, hackers in Russia. That’s, you know, pretty clear and, and same thing for China. And then also too, unfortunately, some of those other countries in Southeastern Asia, Cambodia and Thailand, um, as I understand it, and may- and probably others, who knows?
[00:10:32] Paul McCarty: Um, but, uh, and I, I, well, I think you and I heard recently also some African, um, countries too as well. But I think aside from the fact that they would be operating from those other jurisdictions, um, I don’t think there’s any real collaboration, because I think we have to understand the intent of what North Korea in particular is doing, which is they’re, they’re keeping the country afloat, right?
[00:10:57] Paul McCarty: They are, they are generating income revenue by stealing crypto and other stuff. And so it doesn’t make a lot of sense for them to be collaborating with Russia, like the state or something, because it’s not like an espionage kind of context. It’s a, we need to make as much money as possible, so why in God’s name would we, you know, share-
[00:11:15] Jenn Gile: Why
[00:11:16] Paul McCarty: would you
[00:11:16] Jenn Gile: share that?
[00:11:17] Jenn Gile: Yeah.
[00:11:17] Paul McCarty: Yeah, exactly. And on the other, on the flip side, um, you know, from a Russian criminal actor perspective, they’re in the same kind of boat. Do they do the same thing? No. But, you know, they’re in the same kind of boat, really. My precious, my precious. They’re trying to keep all that, that loot to themselves.
[00:11:32] Paul McCarty: So I don’t see that there’s, like, a… And, and because we don’t see a lot of espionage, um, you know, software supply chain attacks coming out of DPRK, um, I don’t think they’re, they’re driven by that need to collaborate with other state actors. That having been said, I think that there, in other ways, there is some areas where they are, maybe the collaboration’s not the right word, but, like, kind of overlapping in terms of tradecraft and, like, shared resources and maybe, like, infrastructure.
[00:12:01] Paul McCarty: But other than that, nah
Does malicious open source target specific countries or regions
[00:12:03] Jenn Gile: Yeah. Um, so a related question that I got before the event from a fellow attendee is, um, are we seeing malware specifically targeting, and I’ll just say country X, because I don’t think it matters which country. Uh, so, you know, in general, the question is, you know, are we seeing targeted malware that’s going after a specific country or region?
[00:12:28] Jenn Gile: And, um, what we’ve historically said, and remains true, is no, we actually, we don’t tend to see that pattern, um, in the way that you might see it with like a phishing campaign or like we see this a lot with like the, the ad, uh, you know, malware ad campaigns and things like that, but those are very regional.
[00:12:51] Jenn Gile: Um, with software supply chain security, they tend to target technologies, and it may be that certain technologies are used in certain regions, and there could be, you know, connections with that. But for example, what we see a lot of is whatever the latest hot tech is, and, and when I say latest hot tech, I don’t mean like, I don’t know, the new iPhone, but, um, you know, whatever new software, uh, open source ecosystem people are developing in, um, that tends to be where the threat actors go.
[00:13:24] Jenn Gile: And that’s for two reasons. One is there’s not a lot of history in those ecosystems, so everything looks bad. You know? It’s not like a more established ecosystem where you might… I don’t mean everything looks bad, but you’re not looking for like, “Oh, this package is five years old,” or, you know- Right
[00:13:44] Jenn Gile: something like that. Like, it’s just- It’s all new … they don’t have a… It’s all new, so- Yeah … it’s a lot easier to fit in. Um, the other reason that they do it is there’s a lot of people, like, going to that ecosystem who may not have the skills necessary to, like- Uh, consume open source safely. And so it’s just like a really great opportunity for them.
[00:14:06] Jenn Gile: So we tend to see a lot of that. Um, obviously we see a lot of that specific to crypto and Web3 because the overlap here is it’s usually financial motivation. Uh, we’re not seeing a lot of nation state on nation state attacks necessarily. Um, Paul, you said that there, there’s some examples that you can think of that might like skew a little bit more regionally based on development habits maybe.
[00:14:37] Paul McCarty: Yeah, for sure. I think it’s, it’s not even development habits so much as like things that are specific to an ecosystem. So for example, the WhatsApp payment stuff, that’s huge. And so basically- Mm-hmm … in Southeastern Asia, there’s just a ton of emphasis in software supply chain attacks on, um, uh, basically, uh, overwriting or, uh, uh, it’s, it’s complex.
[00:14:59] Paul McCarty: But basically what the bad guys are doing in, in Southeastern Asia is they’re targeting other people in Southeastern Asia to make them send their payments to the wrong WhatsApp address. Um, and so they have like the, there’s all these Baileys, um, copycats, um, which is a, which is a WhatsApp logging, um, library, but that’s because in that area they use WhatsApp payments a lot, right?
[00:15:26] Paul McCarty: And they found this set of hacks and this kind of methodology and this workflow that works there. It doesn’t work really well outside of that target area. And then I can think of a bunch of other different examples in different parts of the world too as well. And even back to what you were saying about the, the marketing stuff, the reason they target, for example, US is because the consumer trend is there, the consumer ability that…
[00:15:48] Paul McCarty: So basically you’re not gonna target a poor country for marketing spend in those areas. Instead you’re gonna target, you know, wealthy countries that are used to buying that way. And, and so I think it’s driven, to your point later, I think it’s driven by the audience, um, and the context of that audience that you’re trying to target to.
[00:16:07] Paul McCarty: Um, and there’s a bunch of, you know, there’s a bunch of kind of regional versions of that all over, much of it having to do with payments. So there you go.
Is DPRK using AI to close a skills gap
[00:16:16] Jenn Gile: There you go. Yeah. Uh, okay. Kind of moving, uh, laterally a little bit. So we were talking, of course, about DPRK yesterday. Um, had a question after the session.
[00:16:30] Jenn Gile: Um, well, let me rewind a little bit. I think that there is still… And it’s interesting 'cause we’re in Europe, uh, Americans are not in the majority of attendees here at this conference. There’s lots of Europeans, there’s lots of people from everywhere, and I’m seeing a little bit of the same bias that we see in the United States of like, it’s a little hard to believe that North Korea is capable of this.
[00:16:53] Jenn Gile: So that’s my setup. So the question that I was asked was, “Are they able to do this because of AI?” And, um, I unders- That’s why I say the, the setup first because that question is coming from an assumption that they’re not sophisticated, that they’re not experienced in this area. And so, um, I won’t say that they’re not using AI, but we, our opinion, and I wanna be clear, it’s our opinion, is they don’t need it in the way that some of the less mature threat actors absolutely do.
[00:17:29] Jenn Gile: You know, like what we saw with Team PCP. We know on one hand they were being mentored by a more experienced person, but they were also very clearly using some AI with their development.
[00:17:38] Paul McCarty: For sure.
[00:17:38] Jenn Gile: Um, we see more of a pattern with the North Korean malware of what you would expect from an experienced developer, you know, leveraging AI tools in their development processes.
[00:17:50] Jenn Gile: So yeah, sure, they’re using it, but it’s not like it’s closing an experience gap in the way that it is with other threat actors.
[00:17:59] Paul McCarty: Yeah, it’s all true. I think that that observation or that question, uh, you know, really kind of accentuates the ignorance of the, the, the person asking that. And that sounds harsh, but my, my point is that them not understanding that North Korea is the heaviest hitter in the software supply chain space by, by a, a couple of miles, right?
[00:18:19] Paul McCarty: Like this is… And so-- And they just don’t know that, right? Like the, the reality is that a lot of people we talked to didn’t realize that North Korea is paying for its ballistic missile program and its other, and its military buildup. It’s not just the missile program, its military buildup with money they’ve stolen from Contagious Interview, more than two billion dollars last year.
[00:18:41] Paul McCarty: They just… People didn’t know that. And I think that when they do know that, that suddenly, like, it kind of like they, they go out of one dimension into a parallel dimension where now that they know that, they realize, “Oh, shoot, I almost messed up.” Um, oh, shnikies, um, uh, you know, they’re actually a, a heavy hitter.
[00:19:00] Paul McCarty: They’re, they’re a mature, um, uh, you know, player in that space, North Korea is, you know? Um, so yeah. I mean, I guess that’s all to say that, you know, it’s just, I guess we know it, and that person just didn’t know it, but now they do.
[00:19:15] Jenn Gile: Yeah. Well, uh, I think, um… Let’s see here. I’m looking through my notes of some of the interesting things that we discussed with people over the last couple of days.
Why GitHub allows git history to be rewritten
[00:19:28] Jenn Gile: Um, one of the topics we discussed in our session, and actually was discussed in one that we watched previously on IT Workers, um, was the ability to manipulate, uh, GitHub’s data, your Git data, around, um, when commits were pushed, who pushed them, what was pushed, all that kind of thing. Um, it was relevant in the IT Worker one for kind of separate reasons from the reason it’s relevant for PolinRider in that, um, the threat actor malware is able to, um, infect your GitHub and force push these commits that have no, uh, I was gonna say paper trail, uh, bit trail, whatever it is.
[00:20:16] Jenn Gile: When you look in the GitHub website, like if you’re in the web UI, you’re not gonna see any evidence. And, you know, the question came up, um, and this is kind of like a twofold question. Like, why does GitHub allow you to do this? Why can you completely, uh, fabricate your Git history? Because, you know, you can use these techniques to make your GitHub account look older than it is.
[00:20:43] Jenn Gile: You can use it to make it look more active than it is. You can use it to hide commits. You can use it to make it look like commits happened that didn’t. So, like
[00:20:56] Jenn Gile: Let’s talk about why we think- Sure … GitHub made this choice however many years ago that they made it. 'Cause they didn’t make this choice thinking, “Oh, let’s make it super easy for people to commit fraud.”
[00:21:07] Paul McCarty: Right.
[00:21:07] Jenn Gile: They had a, a legitimate reason, and whether we think this choice should still be something that’s possible right now.
[00:21:14] Paul McCarty: Well, I mean, I think that if we continue to use Git, and I feel like the whole world has kind of landed on Git, we’re kind of stuck. So the problem is Git. The problem… Well, that’s not true. The problem is Git, and then the fact that… All right, so let me take us back, a step back, and I’ll say the things that I said yesterday in other places, which is that, excuse me, commit history happens on the local workstation.
[00:21:37] Paul McCarty: So as you’re changing code, and you gi- uh, and you git commit, and you store those commits up, and at some point then you then push to, uh, remote, right? And the, that when it’s remote and it’s GitHub, or by the way, GitLab and everybody else does the same thing, they just accept the history that, that is sent with that Git push.
[00:21:59] Paul McCarty: And, um, you know, so if there’s 20 or 30 or 200 commits that are all kind of rolled up in that one push, you know, they just trust that. And I think the problem is that when people go to GitHub and they look in GitHub at a particular set of files in a repo and they see those timestamps, they think those things are being o- you know, originated, or the origin of them is from GitHub, and it’s not.
[00:22:22] Paul McCarty: It’s from Git itself. And Git was designed in a time, a long time ago before, you know, authentication for, for, you know, this kind of stuff was built into it. So Git itself doesn’t have any authentication whatsoever. You set up, when you configure it up, it asks you what’s your email, what’s your username, and that’s it.
[00:22:41] Paul McCarty: And so when you push to GitHub using GitHub credentials, it still takes that username from that commit and adds it. So even though it’s my credential, it looks like it’s Linus Torvalds in, in GitHub. So, um… And now GitHub has made a few things like now about… Well, not really. I was about to say they did some things about being able to see those fake personas, but they haven’t.
[00:23:07] Paul McCarty: And this is the reason that signed commits were- Well,
[00:23:09] Jenn Gile: they’ve talked about… I was literally just gonna say that. Yeah. Signing your commits is, it’s, it’s more like we can’t change this behavior, but if we start to opt in to some things like signing commits, at least it becomes easier for you to be like, “Oh, well, that commit’s not signed, so it must not be legitimate.”
[00:23:27] Jenn Gile: So it’s a little, like, it’s kinda tough because it means you’re looking for the absence of something to indicate that it’s bad- Right … instead of the existence of something. Um, but yeah, I think this does come back a bit to understanding how code is written, that it’s written locally on the developer machine, then it’s pushed to the cloud via GitHub.
[00:23:48] Jenn Gile: You know, GitHub being the cloud. And then from there it’s pushed out to, you know, whatever distribution channels, npm, et cetera. And so understanding that there’s this multi-stage process of things linked together, and it’s not all one program, it’s not all one… You know, you’re not just, like, logged into You don’t have to be connected to the internet to write code, I guess is the, the net of this, right?
[00:24:13] Paul McCarty: Right. Yeah, and GitHub wasn’t- Okay … GitHub wasn’t designed with any of that authentication stuff in, in it. So it’s, you know, we’ve added this later. Anyhow, go ahead.
Could GitHub do more to stop PolinRider
[00:24:21] Jenn Gile: Well, since we’re picking on GitHub, uh, the next question that I got, uh- … this very nice gentleman from Italy came up and, you know, “Lovely presentation, super interesting, but, like, couldn’t GitHub just stop this?”
[00:24:36] Jenn Gile: Uh, meaning couldn’t GitHub stop the spread of PolinRider, uh, in GitHub repositories? And this is, this is a tough one because I think our opinion, Paul, is yeah, they could. Um, you know, we’re looking for signals. Um, you know, we literally just concluded another hunt. I was looking at the data. We have over 9,000 confirmed compromised repositories in our database that were compromised by PolinRider.
[00:25:09] Jenn Gile: And, you know, you did this as well as we’ve gotten some contributions. Mm. You know, all you gotta do is look and you find- Yep … thousands of them. And so yeah, I mean, could GitHub be doing what we’re doing and either- Proactively, you know, prevent certain signatures. Like if they see a certain signature say, “Whoa, whoa, whoa, you gotta stop.”
[00:25:32] Jenn Gile: Um, or could they be, uh, retroactively, you know, scanning for these and do something? Yeah, there’s no reason they couldn’t do it. Um, but it’s kinda not their business model, and that’s the reality. It’s not their business model, and it’s not how their security team is staffed and empowered to, uh, respond. I don’t know.
[00:25:55] Jenn Gile: Well, they make- Do you have a spicier take than I do?
[00:25:58] Paul McCarty: Well, I don’t know. Maybe, maybe this time, no. But, um, I mean, I guess they make such a big deal of some of these things they do, right? And it’s like, uh, it’s kind of… It kinda seems like, you know, I don’t know, a used car salesman that says, you know, “Oh, you know, we’ve put tires on the car.”
[00:26:19] Paul McCarty: And but then, you know, it’s like falling. I don’t know, it’s not a very good metaphor. I didn’t really think it through, but anyhow.
[00:26:23] Jenn Gile: Maybe it’s more like, uh, we put some ground effects and gold rims on, but, like, you need a new, new set of… The rubber is, like, worn down on your tire tread.
[00:26:31] Paul McCarty: It’s still a '91 Accord.
[00:26:33] Paul McCarty: Yeah. It’s still a '91 Accord, right?
[00:26:35] Jenn Gile: Yeah.
[00:26:36] Paul McCarty: I, I, uh… All right, so getting back to the quest- the heart of it. Listen, I mean, the scale of w- A project I did years ago, I don’t know if I’ve ever even shared this with you, Jen, is that I sat there and just watched the API event, API for like months to identify- Hmm
[00:26:51] Paul McCarty: how many, um, GitHub users are created per minute, and how many, um, repos are pushed per minute. And the answer is- Yeah … you know, it’s in the hundreds and thousands, relatively. Um, so just there’s a lot of volume is what I’m saying. But that having been said, going back to what Charlie said about, you know, the NPM and the Shy Halud, Mini Shy Halud stuff, that it’s a known hash.
[00:27:15] Paul McCarty: Everybody and their brother’s got their hash In the same way, the way that I’m finding… GitHub, here we go. Let me get, let’s get intimate here. Hey, GitHub, the way I’m finding these North Korean malicious packages is I use a s- a known detection string, which we and everybody else and their brother is, you know, has put out there, which is the RMCE and, you know, one that Jen and I have seen eight bazillion times.
[00:27:39] Jenn Gile: There’s
[00:27:40] Paul McCarty: a bunch of them.
[00:27:40] Jenn Gile: But yeah.
[00:27:41] Paul McCarty: I just search in your platform, GitHub, and I find malicious stuff, and I suspect you could be doing the same thing. So maybe that’s something you could do sooner rather than later. Um, I, I just… I’m, I’m at the point now where I’m just so frustrated. They make a big deal about these things that they should have done 10 years ago, right?
[00:28:03] Paul McCarty: And they are so behind the times. Man, I feel like I just wanna unload. And like maybe I’ll save this up for next week, and I’ll just like, “Here’s why GitHub sucks.” But I mean, I love GitHub. I’m, I’m logged into GitHub 8,000 times right now. I’m wearing a GitHub shirt and hat today, but like, at the same time, I think the coffee’s kicking in, Jen.
[00:28:23] Jenn Gile: It
[00:28:23] Paul McCarty: is kicking in, yeah. At the same time, I think at the same time, GitHub is so poorly covering and managing its security that it’s really now gotten to the point where, I mean, it’s almost criminal. I mean, I don’t wanna say it’s criminal, but it’s almost criminal it’s that bad. So like maybe just look for the same signatures I’m…
[00:28:45] Paul McCarty: I have a GitHub repo, a public GitHub repo, GitHub that you can use to find this in your own platform. All right, end of rant.
[00:28:52] Jenn Gile: End of rant. Okay. I am gonna rant a little bit, and then we actually do have a question over on our LinkedIn that I’m gonna pop up. Oh, cool. Uh, so the end of rant is we were talking maybe two weeks ago about a developer who has been, uh, compromised and re-compromised, um, over the last six months, and we’ve been trying to get ahold of him.
[00:29:14] Jenn Gile: Uh, I opened up our, you know, shared mailbox this morning and saw the bounced back email. So I mean, it’s, it’s And the community’s trying to do the right thing by opening issues, by trying to connect with these people on LinkedIn, by trying to email them, you know, contact them through whatever means possible.
[00:29:33] Jenn Gile: But as third parties, it’s really hard for us. You know, if, if their email is no good, if they’re not paying attention to their issues, you know, we can’t… It’s really hard for us to do anything about it. Uh, GitHub has these people’s contact information, could get a hold of them and could say, “Hey, you’re, you’re pwned.”
[00:29:50] Jenn Gile: Okay.
[00:29:50] Paul McCarty: Well, and they could, they could take the repo down too as well. They could just take it down.
[00:29:53] Jenn Gile: There’s a lot of things they could do. Yeah.
[00:29:55] Paul McCarty: Yeah. Hundred percent.
[00:29:56] Jenn Gile: I don’t know that I advocate for taking it down 'cause you could break a lot of stuff, but yeah, we could argue that. It has malware in it. Okay.
Audience questions from LinkedIn
[00:30:02] Jenn Gile: So it does have malware in it. Uh, so we have some comments over in the, um, LinkedIn event. So Mark, uh, has joined us. He’s left a couple, uh, comments. Hey, Mark. Happy, happy to have our audience here. So, um, back on the, the comment that we made a little bit ago, he says, "Why do you think people still believe it, that North Korea is not a competent state actor?
[00:30:27] Jenn Gile: The supply cha-chain attack used by them surprised me after my return to hunting them." Uh, I’m gonna say that Here, you’re gonna get my spicy side. I think there’s, this, this is xenophobia and, uh, bias at play. You know, we’ve been making fun of North Korea as a, a planet for a while, and, um, you know, there’s just a lot of, like, cultural narrative that they’re incompetent, that they’re run by a despot who doesn’t know what he’s doing.
[00:31:00] Jenn Gile: Like I, I honestly, I just think that it’s groupthink, um, that has allowed- Mm … them to be so successful. I think their success is in large part because people don’t take them seriously. If they were China or Russia or Iran, there would be task force pointed at it. Um, but you know, you have, uh, stunts by people like Dennis Rodman going there.
[00:31:25] Jenn Gile: You know, you have our president, um, talking about, you know, thinking that they’re great. Like it… No one takes them seriously, uh, for other things, so why would you take them seriously for cyber crime? That’s my, my thought of why it’s just so hard for people to believe that they’re as sophisticated
[00:31:44] Paul McCarty: as they are.
[00:31:45] Paul McCarty: Yeah. I, I think there’s a couple other things too that are important. I, I agree with everything you just said. Like genuinely. I’m not… Like, I totally agree with that. I th- it’s definitely, um, groupthink. But here’s, here’s some other kind of contributing factor, and Mark, that’s a really good question. Um, and I wish it wasn’t like this.
[00:31:59] Paul McCarty: But the other thing is that North Korea does not do ransomware. And the whole enterprise, I’m… I get every time I go to one of these conferences- That’s fair,
[00:32:07] Jenn Gile: yeah …
[00:32:08] Paul McCarty: um, every time I w- I go to one of these conferences, and I’ve been going to these conferences for a long time. Every time I go to one of these conferences, I’m reminded that the enterprise security architect only cares about ransomware.
[00:32:20] Paul McCarty: They don’t even really care about info stealers. It’s bizarre. Like, they are singularly fo- that’s why they think that EDR fixes everything, right? Because EDR has an answer for, uh, ransomware, because you know, EDR can see that a number of files are being encrypted, and they go, “Oh, look, that’s bad. Let me stop it after 10 or 15,” or whatever.
[00:32:37] Paul McCarty: But like, part of it is that they don’t do ransomware. There’s a couple other things too as well. Uh, the first of which is that the, the types of attacks that we are concerned with at Open Source Malware, software supply chain attacks, don’t really get a lot of visibility for the enterprise security architect type person, like SecOps person, right?
[00:32:58] Paul McCarty: And this is, you know, driven home again every time I go to one of these conferences. So I think between those things, there’s just not a lot of visibility and understanding of it. And here’s the thing too, is that North Korea now has somewhere between 60 and 100 nuclear missiles. Like, that’s roughly the equivalent of Uh, Israel.
[00:33:17] Paul McCarty: And so they are a nuclear power, um, you know, and this has happened on our watch. Um, and they’ve done it with money that they stole. So, um, the, you know, it- if you’re not taking them serious, then that’s kind of on you for, you know, not looking around, right? It’s like, if I’m only looking at the ground, I miss the fact there’s a pterodactyl about to pick me up and eat me.
[00:33:40] Jenn Gile: Well, I would say I agree with you on the comment about the type of attack certainly is not what, um, people are more likely to be paying attention to. Um- Agreed. Okay, another comment from Mark. Um- Curious, uh, liability and provide privacy business fear by GitHub. Uh, he says he’s just playing devil’s advocate.
[00:34:06] Jenn Gile: He’s aligned to your viewpoint. Um, yeah, I mean, if GitHub said that they were gonna take responsibility for preventing malware, and then they didn’t, yeah, there could be some liability there that they’re concerned about. You and I have talked about this before, Paul, that if you-
[00:34:27] Paul McCarty: Yeah …
[00:34:27] Jenn Gile: uh, don’t make a claim that your platform is secure, then it’s a lot harder to sue if your platform’s not secure or if bad things happen to you in that space.
[00:34:36] Jenn Gile: So yeah, I, I think it’s a nuanced problem, and there are probably, in addition to like staffing reasons, there’s probably a lot of reasons that Microsoft has made the decision not to, um, be more restrictive on GitHub. I don’t personally know a lot about GitLab, but I know they have a very different business model.
[00:35:00] Jenn Gile: Um, you know, it’s not this massive number of free accounts, and so you might like look at what do other SCMs do that’s different and, you know, because they’ve chosen to be more enterprise, perhaps they have different policies as a result. You know, when you have m- mostly a large free user base, it’s different.
[00:35:21] Jenn Gile: Paul, of course, you’re more fam- familiar with GitLab than I am.
[00:35:25] Paul McCarty: Yeah, I would say, listen, I, you know, I have my, you know, I’m not certainly… Uh, let me skip that part. Um, GitLab has-- Basically, they’ve got-- they, they have, um, hired and built out a better security apparatus. They take it more seriously. That’s what it comes down to.
[00:35:43] Paul McCarty: They take security more seriously, and they build it in. They’re much more responsive. Are they perfect? No, of course not. But, um, you know, they had a significant sec op and red team and just had built for a sm- much smaller company. They built out a security apparatus and, and, and showed the world, at least to the way I see it, showed the world that, hey, we take this seriously.
[00:36:06] Paul McCarty: GitHub doesn’t do that, seriously. Like there’s like, you know, most of the people, security people that are there that are-- well, were there are gone. Um, they’ve outsourced, you know. I know we’ve said this before, but they’ve outsour- outsourced a lot of the things. I currently have in multiple, multiple tickets for things that are malicious, and it’s taking ever longer to get those things taken off of either NPM or GitHub So th- you know, maybe this is just another opportunity for me to kick GitHub, but I mean, there’s just…
[00:36:34] Paul McCarty: That, you know… Oh, oh, I know. But I was gonna say to Mark’s question, liability, I think that, um, here’s the thing, is that, that plank has already been broken, right? That, that horse is already bolted. So they, they, they’ve already said they’re scanning for malware. They’ve already done a number of other things.
[00:36:49] Paul McCarty: It’s just not effective, right? And so I don’t think they can make the argument anymore, the, “Oh, y- hands-off approach, so we’re not liable for it.” No, they know they’re liable for it, and yet I see more, like, malware and stealers hosted on GitHub now than I’ve ever seen before, right? So, you know, whatever they’re doing is not working, so-
[00:37:11] Jenn Gile: Yeah.
What developers should actually do
[00:37:12] Jenn Gile: We, we- Okay, two more questions- … we’ll end on that … and then, uh, we’re going longer than we thought we would. So, uh- Right … good job us, I guess. Um, so I, uh, also had, uh, someone who was, like, genuinely like, "What can we do about this problem? What can we do about developers, um, consuming, you know, poisoned GitHub, you know, forks, uh, poisoned NPM packages?
[00:37:37] Jenn Gile: What can we do to help them?" And, um- Their suggestion is can’t we just give them YARA detection rules that would look for the same things that we’re threat hunting for? And, um, I say that with a smile because it’s, it’s so well-intentioned. Um- It
[00:37:57] Paul McCarty: is …
[00:37:59] Jenn Gile: but, uh, unrealistic in terms of how developers work. And so, Paul, again, you have more experience with YARA rules than I do.
[00:38:08] Jenn Gile: So, like, in a balanced way, how would you explain why, like, much in, you know, some of the other ideas that can come out of the SecOps side that just won’t work for the, the engineering side, why would you say YARA rules for developers is not- Yeah … the best solution?
[00:38:25] Paul McCarty: I mean, there, there’s a whole bunch of reasons. Like, and are, are YARA rules, you know, uh, effective to some degree for software supply chain, uh, malware? Yeah, for sure. Like, a bunch of our competitors, you know, use them, and that’s how they… And, and when you read their, you know, the descriptions of, not our competitors, but people that are, you know, finding malicious packages, and when you read their descriptions, clearly it come from a YARA rule.
[00:38:50] Paul McCarty: But, I mean, at first, u- using YARA rules kind of skips the fact, kind of bli- belays the, the, the point that they don’t understand how the bad thing gets to you. So, like, it’s, it’s a dependency named in a package manifest. And so for your YARA rule to work, you’d have to have something that’s kind of the equivalent of software composition analysis that pulls each one of those things, runs a YARA rule against it, pulls all their dependencies, runs a YARA rule against, pulls all their dep- and so on and so forth, right?
[00:39:21] Paul McCarty: And it’s just… So, you know, effectively it, you know, from that perspective, it, it’s not the right tool for the right job. And that’s the important thing to know about YARA. YARA is great and, you know, and, and I’m glad if you’re using it. But then the other thing is that YARA only works if there are signatures and regex that you can look for.
[00:39:44] Paul McCarty: And the reality is that, like, DPRK is a great example of this, you know, these campaign markers that they use are ever-changing 'cause they’re, they’re creating new special snowflakes, but each one of the things is a special kind of unique way of building it, and it’s different from the last one. So, you know, being able to find those things that you can, you know, YARA rules will actually be able to find and parse out just don’t exist.
[00:40:07] Paul McCarty: Um, um, and they’re getting better. Their obfuscation’s getting a lot better. Um, so, you know, being able to pull anything discernible out of it is hard. So YARA is not the right tool for this. Um, uh, and certainly getting
[00:40:23] Jenn Gile: that to arm- Well, so let’s talk about what is the right tool and then wrap up from there.
[00:40:26] Jenn Gile: Um, so as you and I have talked about for the last few months, this campaign in particular targets individual developers. And in general, you know- When somebody’s consuming a compromised asset, it’s an individual making that choice. It’s not a company has made the choice. Um, and so I think, like, let’s set aside things like package firewalls and, uh, registries 'cause that’s just not realistic for a lot of people.
[00:40:56] Jenn Gile: Um, the first thing that I would do if I were taking a look at a repo to fork or a package to download is I would look for the presence of a VS Code folder, uh, in the GitHub. And I would look for a task JSON file. That’s the first thing I would do. Um, 'cause, you know, there’s a lotta, a lotta indicators you could be searching for, but you can…
[00:41:21] Jenn Gile: Like low-hanging fruit, it takes me two seconds of looking to see, oh, there’s a task JSON file that’s saying I’m gonna auto-run… Oh, it’s gonna auto-run, you know, this file right here. Like, that’s a concern. Um, so, you know, what we’ve talked about is the reason VS Code is such a nice attack vector, uh, or rather auto-install your malware, uh, feature for threat actors is because developers don’t look at the, the task JSON file.
[00:41:51] Jenn Gile: And so I would say look at that file, see what it does. Um, there’s lots of other things you can and probably should be doing, but that’s, that’s what I would say.
[00:41:59] Paul McCarty: Yeah, also look for the, the fa-solid-900.woff2 file.
[00:42:05] Jenn Gile: Look for fonts. And I’m gonna say, like- Fonts not fonts? Yeah, fonts that are not fonts. Um, we’re seeing, uh, two types of- Uh, delivery mechanisms.
[00:42:17] Jenn Gile: One is this fake font thing that started at the end of 2025, and the other is, um, poisoned config files. Uh, the fake font one candidly is pretty easy to spot. The poison config files are harder because it’s not just one or two files that they’re going after. It’s like anything that’s a config.js or ts or .mjs.
[00:42:38] Jenn Gile: Like, it’s such a huge breadth of config files, so like scanning those config files for obfuscated JavaScript would be the other top tip.
[00:42:50] Paul McCarty: Yeah. Well, 100%. Um, uh, and, and they’re now going after not just the config files, now they’re dropping an app.js and database.js and all kinds of other stuff. So they… I, I mean, really now you have to- They’re making it,
[00:43:02] Jenn Gile: uh, real hard.
[00:43:03] Paul McCarty: Yeah, they’re making it… So, so basically any .ts, .js, .waf2, and .cjs, .mjs, um, and there’s actually several more too as well. E- even, they’re even dropping that on, on, um, certain other, um, like YAML files and stuff like that, that they have a command string. But the point is that, you know, it’s hard to find this stuff, um, and it’s ever-changing.
[00:43:28] Paul McCarty: Um, and that’s just not the kind of thing that a, a YARA rule is built to look for. So YARA’s part of the solution for sure. Um, but also understanding what the thing does and, and YARA doesn’t help you, for example, if you’re pulling a dynamic dependency, right? And this is something that as people move away from, uh, as bad guys move away from lifest- life cycle scripts, pre- and post-install scripts, they’re gonna start focusing on how to bring something into the, to the package dynamically.
[00:43:55] Paul McCarty: Um, and, and that’s, you know, YARA is gonna have a really hard time touching that, so.
[00:44:00] Jenn Gile: Yeah. Uh- Let’s see. Is there anything else we need to cover? There’s so much. Oh, you know what? The whole reason that, um, the question about AI came up was because in many cases it helps threat actors, uh, translate their malware for other ecosystems.
[00:44:18] Jenn Gile: Mm. The super interesting thing to understand about PolinRider is it’s all JavaScript. They’ll put it anywhere and, um- Right. … you know, I was looking at, uh, a developer’s repositories two days ago as we were preparing for this talk. We had somebody reported a Go package or a Go module that had been, uh, compromised.
[00:44:38] Jenn Gile: So I went upstream, and I was like, “Oh, interesting. Almost all of this guy’s stuff is C#. I wonder, like, if he’s still gonna be compromised.” And sure enough- Right … it was in his C# repos. It was in, uh, he had some other languages that were not, you know, JavaScript, TypeScript, et cetera. So I guess the thing to understand is you’re not safe- Yeah
[00:44:58] Jenn Gile: just because you’re not a JavaScript shop. Right. Uh, it is, it’s a, it’s great. It’s great if that’s your, your MO.
[00:45:09] Paul McCarty: That’s a great point, and I just wanna really quickly drill in a little bit more just so people that are listening understand what’s happening. So your lang- the repo can be any language you want, and what they’re doing is they’re dropping in a VS Code tasks file, which is gonna auto-run when on folder open and do all that stuff, and then they’re dropping in a malicious JavaScript payload that gets run by the task file.
[00:45:29] Paul McCarty: So it doesn’t matter whether the rest of it’s PHP or C# or whatever the hell it is. As soon as you open that up in VS Code, it’s gonna run that task file, it’s gonna run the malicious payload, which is a JavaScript, and you’re done. Um, so yeah, it’s, it’s a good point to bring up.
[00:45:45] Jenn Gile: Uh, and I wanna end on just one thing, uh, in the comments here.
[00:45:49] Jenn Gile: I like to treat devs security, uh, offset consultants, development pipelines as an enterprise threat, not as a traditional enterprise security problem. The whole spicy. Uh, I don’t, I actually don’t completely disagree, uh, because PolinRider basically does turn your developer into an insider threat. They have no idea.
[00:46:11] Paul McCarty: All right, here we go. You ready for this? Instead of zero trust, zero dev trust.
[00:46:17] Jenn Gile: Oh, we’re gonna break some hearts here. Okay, why don’t we wrap it up? We’ve gone way over our normal time. I think between- I’m a dev. I’m a dev, by the way. … you and I being, like,
[00:46:24] Paul McCarty: we’re
[00:46:25] Jenn Gile: extra caffeinated today. Right. Yeah. Um, and so let’s end on that.
[00:46:28] Jenn Gile: Um, we’ll be back at our regular bat time, bat channel next week.