BLOG

The OpenSourceMalware Show #16

Live from Hacker Summer Camp! Keyv and cacheable npm worm, WEL1DROPPER AI slopsquatting campaign, NullReceiver DPRK C2 technique.

By cb482791-4ef1-4762-96ad-b0ca4bdd538e ยท

The OpenSourceMalware Show #16

The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.

This week we talked about:

  • New npm worm hits Keyv and cacheable: Jared Wray's GitHub account was compromised on Tuesday, and threat actors used it to publish a worm based on the open-sourced Mini Shai-Hulud malware. The worm spread to over 400 packages, with ServiceTitan alone losing 100 packages, and it searches developer machines and CI runners for credentials across GitHub, npm, AWS, Kubernetes, Vault, Azure, Google Cloud, Terraform, Docker, and Slack before exfiltrating them. We also talk about how this got caught within minutes despite GitHub's recent claims of proactive pre-publication malware scanning.

  • WEL1DROPPER floods npm with AI slopsquatted packages: Over the past 72 hours, more than a thousand malicious packages have been published to npm as part of a campaign we're calling WEL1DROPPER. It doesn't rely on install scripts at all, executing instead when a package is imported, and we believe it's loosely connected to the earlier Moika campaign based on shared tradecraft. We dig into why attribution to Russian threat actors is complicated given the campaign also targets Russian and Belarusian financial institutions.

  • NullReceiver, DPRK's new C2 technique: We found DPRK-linked malware hiding its C2 IP address inside the recipient address of a completely empty Ethereum transaction, an evolution of the EtherHiding technique that fixes its biggest weakness: a fixed, publicly known destination address. We've confirmed at least 10 packages using this new technique so far.

Resources

[00:00:00] Jenn Gile: Hey, it is Friday, August 7th. Uh, recording on a different day this week because Paul and I are in Las Vegas. We're live from the Westin, uh, right before we head over to, uh, LVCC for DEF CON. So we wanted to sneak in a, uh, podcast and an episode so we could talk about three things that have happened in the last week.

[00:00:25] Jenn Gile: Um, but before we get there, uh, Paul, what are your kinda like, uh, impressions so far? We've been here since Sunday. We did Las Vegas. Uh, besides Las Vegas, we did Black Hat, obviously starting on DEF CON. Lots of events, lots of people to see. What's your takeaway so far?

[00:00:43] Paul McCarty: AppSec buyers are very different than SecOps buyers.

[00:00:47] Paul McCarty: Um, uh, I think that, that my takeaway is that, um, the industry is waking up to the reality that software supply chain attacks, um, are real and present and, and a danger. But I think a lot of people still don't really understand how it moves. Um, and I guess that's why we're here, right? That's why we're doing what we're doing.

New npm Worm Compromises Keyv and Cacheable

[00:01:09] Jenn Gile: Yeah, fair enough. Um, so unfortunately, predictably, on Tuesday? Yeah. Yep. Tuesday, uh, we all collectively woke up to a new NPM worm. Uh, we kinda figured after the success that Team PCP had during, I don't know, Hacker Spring Break, whatever you wanna call the set of things in San Francisco back in March, um, that we figured an attacker would try to pull the same thing this week.

[00:01:38] Jenn Gile: So, uh, pros and cons. Uh, on the positive side, this thing didn't go as crazy. Um, there's some scuttlebutt that the attackers didn't quite, uh, do things in the, the most complete and high-quality way. Uh, but on the negative side, uh, over 400 packages were affected by this worm. Um, we've been in communication with the person who, as far as we can tell, was the, the patient zero, um, Jared Wray, who maintains, I don't know if it's Keyv or cave, I don't know how you pronounce it, and, uh, cacheable, but he mains a ca- maintains a couple projects.

[00:02:23] Jenn Gile: Um, his account was taken over on Tuesday. He was locked out for at least it seems like maybe 12 hours while threat actors published the worm and then, uh, it made it into, you know, other parts of the ecosystem. Um, what, uh, what do you think is notable here?

[00:02:46] Paul McCarty: Well, I think the first thing that's notable is that while you're right that the threat actor in this case, we don't believe that this is a, a highly competent threat actor to...

[00:02:57] Paul McCarty: I should choose my words carefully. Um, but that said, my, my point I'm driving at here is that even though this is not a highly competent threat actor, at the same time, this was still a very, unfortunately, a very successful attack in the sense that it, it infected a lot of packages, had a lot of reach. Um, Jared's packages alone, you know, are downloaded a lot.

[00:03:19] Paul McCarty: Um, so it just goes to show you that, you know, even if somebody fumbles the hand grenade, it's still pretty fucking dangerous.

[00:03:27] Jenn Gile: Yeah. Uh, there's one particular ecosystem that just got, uh, decimated by this, a company, a service called ServiceTitan had 100 packages compromised. Uh, I don't know if that's all of their packages, but that's certainly a lot of packages, and that seems to be the biggest, um, single impact that we're seeing with this attack

[00:03:51] Paul McCarty: Yeah, and we also heard some inside baseball that this might be related to a long-lived legacy path.

[00:03:56] Paul McCarty: We haven't verified that yet, but if that's the case, just goes to show you, I'm sorry, how dangerous this is.

[00:04:07] Jenn Gile: Poor Paul, uh, has been hit with a cold this week. It's not the, uh, you know, security plague that might catch us, uh, off guard, but kind of while he's recovering. Just in brief, you know, what the malware did is it contains, uh, an obfuscated JavaScript payload, and it has either a math underscore init.js or math underscore symbol.js file.

[00:04:31] Jenn Gile: They both have the same payload. It's, uh, roughly the same file hashes. And what it does is it searches your dev machines, your CI runners for credentials. Surprise. Um, it's looking for GitHub, NPM, AWS, Kubernetes, Vault, Azure, Google Cloud, Terraform, uh, Docker, Slack, like pretty, uh, diverse kind of like infrastructure-related credentials.

[00:04:57] Jenn Gile: Um, it exfiltrates what it finds. Um, what we, uh, know so far is it's based off the open-sourced Mini Shai-Hulud worm that came out from April, May timeframe. Um, and it, uh, let's see here. It does use the GitHub dead drop in the same way that we saw Shai-Hulud do last year. Hey man, do me a favor and mute. We got, we got an echo chamber.

[00:05:27] Jenn Gile: Sorry everyone, we're sitting across the table from each other. It, it gets a little funky sometimes. But yeah, they've got, um, GitHub dead drop. Uh, they have a primary way of exfilling as well. Um, I do believe, correct me if I'm wrong, that this is one that ran on a pre-installer post-install script, right?

[00:05:48] Paul McCarty: Yeah, I think that's correct

[00:05:50] Jenn Gile: Um, I don't know how deep we need to get into it, but the thing that I think is worth, um, having a little bit more of a conversation about is just last week where we're talking about GitHub's new announcement where they said that they would be proactively scanning packages, um, pre-publication, looking for malware.

[00:06:12] Jenn Gile: And, uh, this was found by several security reacher- researchers within minutes of it being published. This was not complicated, sneaky malware. And so that means, I guess, one of two things. Either the pre-publication scanning is not turned on, or it's not tuned to find this kind of malware. So, um, just kind of a reminder that just because they say it's turned on doesn't mean it's going to be, uh, immediately preventing these kind of exploits.

[00:06:42] Jenn Gile: Uh, Paul, I'm sure you agree.

[00:06:44] Paul McCarty: Yes, I do. I think that's a great segue to one of the other two things we wanna talk about today. Keeping this- The

[00:06:51] Jenn Gile: massive thing, yeah ...

[00:06:54] Paul McCarty: the pre-publishing, you know, scanning that supposedly is being turned on. And, uh, and my understanding in general is that it's being rolled out gradually, but that's also kind of ignoring the fact that we know that this has been in place for months or, or a year or more.

[00:07:08] Paul McCarty: So they've been using the Microsoft scanning inside of, um, NPM, um, for a while now, and so to say that it's new. So, and yet it's not catching all these big things that we're about to talk about

WEL1DROPPER AI Slopsquatting Campaign

[00:07:20] Jenn Gile: Yeah. So big thing number two, which I would say, uh, is a bit under the radar because it's not a worm, it's not an account compromise, is, uh, yesterday morning, you discovered a massive new campaign that is publishing just hundreds of packages to npm.

[00:07:39] Jenn Gile: In the last now seventy-two hours, we've discovered over a thousand, uh, malicious packages pushed to npm. I'll drop the link to the analysis that we put up yesterday morning. Um, you're calling this the WEL1DROPPER campaign or WEL1DROPPER malware. Um, there's a couple of things that are notable about it. Uh, one is, again, clearly not getting blocked by anything that's coming through on npm.

[00:08:08] Jenn Gile: Um, uh, two, as far as we can tell, uh, attribution looks like, uh, Russian threat actors. We talked about a campaign called Moika a couple months ago. There's reason to believe it may be the same threat actor. We don't see as much, uh, Russian, uh, malicious open source as we do things out of North Korea, obviously.

[00:08:32] Jenn Gile: And then the third thing that I think is... Well, I guess there's a third and a fourth. Uh, the third thing I was going to bring up is this does not, uh, take advantage of install scripts, post-install, anything like that. Um, so if, you know, you're kinda thinking, "Oh, well, if I just turn off npm like lifecycle scripts, I'll be safe," this campaign doesn't take advantage of that.

[00:08:54] Jenn Gile: And then the final thing I'll say is, uh, many of these look to be, uh, a very specific type of typosquat, which is an AI slop squat. Slop squat. Say that five times fast. Um, so yeah, the thing that, uh, to like kinda dig in there is more and more we're seeing malware that's targeting agents, not humans. And, um, these are, uh, much like other typosquats.

[00:09:25] Jenn Gile: They're forks of benign projects that have been, uh, poisoned in some way. Though in- interestingly, in at least one case that you looked at, Paul, uh, you found that it didn't actually do the thing that it claimed to do, so it was both a slop squat and a, I don't know, not a very good package. What do you wanna say about this WEL1DROPPER campaign?

[00:09:52] Paul McCarty: Helps if I go up, up near. Um, yeah, I mean, I think the, the, the WEL1DROPPER thing is, uh, you know, I think people are probably lumping it into the kind of scam junk, um, category like Indonesian Foods. But in this case, the payload is actually very dangerous. Um, and so there's a couple things I wanna talk about here.

[00:10:10] Paul McCarty: You know, we've loosely attributed this to Russian threat actors because they're using their backup stage two is being pulled. Um, well, there's a backup function that will pull the stage two from text records, uh, from a, a .ru domain. Now, I thought that .ru domains, you couldn't buy those in the West, but they're...

[00:10:32] Paul McCarty: You still can buy them until September 1st, 2026. So... And some people have said, some other researchers on Twitter have, have said that, you know, they're trying to make it look like it's Russian. And I agree, it kind of feels like that, but at the same time, this has, um, some, some signals and some similarities to another campaign like we saw in Moika.

[00:10:57] Paul McCarty: Um, I personally genuinely believe that Moika is a real Russian campaign for a number of reasons, some of which I can go into and some of which I can't. But I guess the point is just because somebody uses .ru domains right now at least, doesn't mean that the, the, you know, it's, it's officially attributed to, uh, Russian threat actors.

[00:11:16] Paul McCarty: There were no Cyrillic characters in any of these packages. And this is the weird thing, is that they're targeting mostly Russian and Belarusian financial organizations. So, like, if you're a Russian threat actor, why would you do that? 'Cause you know that's a death sentence in Russia. But here's the other thing, is it also has, like one of them I was looking at had the CIS checks, right?

[00:11:37] Paul McCarty: So it's looking, am I running in Russia? So why would you be targeting Russian, you know, financial institutions if you also have the CIS block there? So it's, it's a confusing thing. But in the meantime, this thing is pummeling NPM. At one point, I saw one package per 51 seconds So, and each one of those, almost every single one has its own email address.

[00:12:00] Paul McCarty: So just the mass, you know, the automation that these threat actors are using to create this stuff. And MPM is, MPM does not have any response. Most of these are being tagged by OSV and us and, you know, and being labeled that way. So I don't know where this pre-publish standing is, guys. Come at me.

NullReceiver: DPRK's New C2 Technique

[00:12:22] Jenn Gile: Okay. Uh, next topic is something that we actually published, ooh, Saturday, I think.

[00:12:29] Jenn Gile: Uh, right as we were, I think you were mid-flights, uh, on your way out to the US. I was, you know, packing my bags. Um, you made a discovery about some new, uh, technique that, uh, North Korea's Lazarus Group is using, or at least it looks like it's Lazarus Group, but it certainly is North Korea. Um, you've named this technique NullReceiver.

[00:12:53] Jenn Gile: It's a new, uh, way for hiding a C2 IP address inside the recipient of a completely empty Ethereum transfer. And, um, you know, if you're more used to the application security side of this, of like, yes, no, is this package bad? You may not know a lot about C2, but essentially once the malware fires, the threat actors have to have a way to get your stuff out of your environment, whether it's, you know, via a rat or something else.

[00:13:24] Jenn Gile: They have to have a way to come in and, and talk to your machine. And, um, they have been using Ethereum, they've been using blockchain technology to do this for at least... Is it two years now that it's been observed? Maybe a little... I don't know. It- Uh, you're on mute, man

[00:13:45] Paul McCarty: Trying to do the, do the needful. Um, no, I think EtherHiding has been around for a year, but you're right, some of the earlier Ethereum stuff goes back, I think, to late 2022.

[00:13:58] Jenn Gile: Yeah, I feel like it's somewhere in there. So, um, you know, kind of what is EtherHiding? Why would North Korea be doing this innovation, innovation? So EtherHiding is a technique that, um, works by sending a transaction to Ethereum's, like, burn address, and they embed the secret, such as, like, a C2 URL or even a malicious script inside that transaction's data field.

[00:14:24] Jenn Gile: And the destination itself is meaningless. Uh, the data field's what matter. And this, um, has been really highly successful at evading detection, uh, from, you know, your EDR, uh, whatever, um, threat detections you have set up because it looks legit and it, um, you know, the Where it says it's going is not necessarily where it's going.

[00:14:48] Jenn Gile: It's the, the memo field, I believe. Uh, but EtherHiding has some weaknesses. Um, it reuses the same fixed public burn address across every campaign, and that makes it much easier for us, thank you, uh, to watch it. That's how GTI caught it. Um, you know, the... If you monitor that burn address and then flag anything unusual sent there, that's kinda the, um, uh, you know, hack, so to speak, to, to be able to manage it, uh, in your detections.

[00:15:18] Jenn Gile: Also, um, it's slightly more expensive. Uh, so Paul, talk about what you discovered with NullReceiver and why it's able to get around, um, kind of the, the drawbacks of EtherHiding. I'll say we've, so far, we've discovered 10 packages that are using this new technique. Um, we're linking it kind of softly to the Contagious Interview campaign.

[00:15:44] Jenn Gile: There's enough overlap there that it looks like it's part of that particular, um, MO. So yeah, lay it on us. What's interesting here?

[00:15:52] Paul McCarty: Yeah. So in, in typical EtherHiding, um, what makes it unwieldy over time is that you use, and you said it, you use the same, uh, blockchain address. And so they, this, this set of blockchain addresses, we've been watching these things now for, like, a year and a half or two years.

[00:16:08] Paul McCarty: Like, they'll be used across... And this is one of the way that, you know, one of the easy ways that you're able to attri- attribute this to North Korea is that, you know, they used it in, in, in some of the early minting stuff, and they used it in, you know, task tracking. Right now they're using it in other places too as well.

[00:16:23] Paul McCarty: But the problem there is that, like you said, they're using specific blockchains. They're using Tron and Aptos, doing the Binance BSC thing. Um, I still don't understand that one, but anyhow, um, and th- those three blockchains have these memo fields. So the, what you enter into the blockchain address itself, you know, is im- immutable.

[00:16:40] Paul McCarty: You can't change it, right? That, that's how the blockchain works. But these memo fields allow you to, to change it. Now, the problem though is that it singularly kind of pivots on that known eth- uh, uh, that Tron address or the Aptos. And everybody and their brother is looking for those. Everybody and their brother and their sister, if you wanna be gender non-specific here, are looking for those, uh, addresses.

[00:17:01] Paul McCarty: So DPRK probably was sitting there in, in, in their Friday hackathons and thinking, "How can we do this in a more lenient way where we can change the, the blockchain address?" They came up with this really unique technique, which is basically what they do is they take a specific Ethereum- Address, and they can change it.

[00:17:19] Paul McCarty: You know, they can change it up if they want to. And basically what they then do is they send a transaction of zero d- uh, zero anything to it. So they, they spend a little tiny bit of, of gas. I think that's how this works. I'm not a crypto guy, not pretending to be one. Um, uh, but they don't have to actually send any, any money to it.

[00:17:37] Paul McCarty: And the, the destination that is, that they're sending that to doesn't exist, right? It do- it's not... You can't send stuff to that destination. But instead, in the address they're hiding, um, they, they only can... There's not a lot of characters there, so they can hide an IP address or a short URL or maybe a very short, like, curl to a, to a redirection string, one of those, like, shortened out GYS or something like that.

[00:18:02] Paul McCarty: They can't put a lot of stuff there. But what makes this really great then is they put that in stage two in front of EtherHiding. So we've already seen this. We've already seen this where... And a couple of people asked me on Twitter, how do, how am I attributing this to DPRK? Well, basically just take the standard six-stage DPRK kill chain with, with, you know, Invisible Ferret and all the other stuff, and they're just slotting in now at stage two, NullReceiver.

[00:18:24] Paul McCarty: And they still have, in some cases they still are using EtherHiding at stage three and four, right? So it's, um, you know, there's, you know... And, and those, and EtherHiding is still calling the original trial run, so they're just hiding it at the beginning of the kill chain. So anyhow, that's me going into depth about how we can, we know it's DPRK and we can connect it to a lot of activity.

[00:18:43] Paul McCarty: 'Cause in those cases where they are using EtherHiding, we can just, you know, point at all those other things. Hundreds, hundreds and hundreds of packages that use those things. So, um, yeah, I'll pause there. The file drop worked.

[00:18:57] Jenn Gile: Good. Excellent. Um, that's kind of the majority of what we had to talk about today.

[00:19:02] Jenn Gile: I don't know that we'll go the full even, like, half hour that we've been doing. But, um, I wanna talk about something you and I got to do yesterday that I thought was kind of special. Uh, our friend Mackenzie over at Aikido, uh, fired up an email, you know, a couple weeks ago and said, "Hey, a whole bunch of us that work in the malware security research space are gonna be in Vegas.

[00:19:24] Jenn Gile: Let's all film a podcast together." And so we got together, uh, yesterday afternoon with Mac as well as, uh, John from Aikido, who, uh, was the CEO of Root, which was acquired recently. Uh, also in the room we had StepSecurity, we had OX Security, and Socket. So, uh, you know, we're a little bit, um, separate from those types of vendors, but certainly they're all direct competitors.

[00:19:50] Jenn Gile: And so I thought that was pretty special. We got to get together and have, like, a real conversation about what's, uh, problematic in the industry right now, what the challenges are, uh, in what ways vendors are making things better and honestly worse in some ways, and, um, what maybe we can be doing collectively.

[00:20:10] Jenn Gile: So I just thought it was such a great example of, like, community and the value of getting out of our basements. My basement, your shed, uh, and you know-

[00:20:23] Paul McCarty: No, it's a cottage. Cottage.

[00:20:24] Jenn Gile: Cottage. Okay. I'm sorry. Well, excuse me. Um, and you know, just getting out and, like, seeing the people 'cause, uh, this is, you know, it's a big world, but also it's really small, and you know, I don't think any of us would be successful if we didn't have the, the connections and relationships.

[00:20:43] Jenn Gile: So anyway, uh, that all is a teaser for, uh, Mac's podcast episode of The Secure Dis-Disclosure that's gonna have, uh, a record-setting, I think, six guests on it. Um, it should be pretty fun

[00:21:00] Paul McCarty: Yeah, and I just wanted to... I don't have anything really to add. I just wanna say thanks again, um, to Mackenzie, and to Aikido for putting it together, and to Socket and Step and Ops for being a part of it.

[00:21:10] Paul McCarty: I think this is the kind of thing that we need to do more, and I think all of us in the room yesterday agreed that we need to do more of this, right? We need to have this kind of relationship where we're not just trying to compete against each other. Are we competing? Of course we are, right? But at the same time, well us not so much, but at the same time, you know, it's important for us all to be part of this community.

[00:21:27] Paul McCarty: Um, so big, big shout to them.

[00:21:30] Jenn Gile: Yeah, and like, uh, the necessity for a collaborative relationship is never more clear than when you and I have these conversations about, "Hey, we just found 1,000 new malicious packages that are hanging out in NPM." You know, what can we, what can we collectively do to try to get them taken down?

[00:21:51] Jenn Gile: Um, you know, we were talking about the situation with the NPM worm, and, uh, ourselves included, multiple vendors, you know, reached out and tried to help this guy because, you know, the person who was compromised is not a security person. He doesn't have the support of a big company. You know, a lot of times they're a little bit like, "Uh, what do I do?

[00:22:13] Jenn Gile: Oh no, uh, this thing that I've, you know, built and taken responsibility for has gotten taken away." And, uh, you know, unfortunately in, um, you know, the case of the person who was compromised, they weren't getting help from more official channels

[00:22:33] Paul McCarty: Yeah, it was really unfortunate, and we've, we've been seeing this, and we've talked about it on the podcast before, but I really think it's incumbent on GitHub and NPM to come up with a better response plan than locking out. And I get, you know, especially when the GitHub repository's sitting behind the NPM packages are also potentially malicious.

[00:22:52] Paul McCarty: I get that locking them out to some extent makes sense. But at the same time, what we then create is we create the situation where the maintainer themselves can't be a part of the fix, right? Um, and so then there's a lot of latency while these, these offshore emails go backwards and forwards with the maintainer.

[00:23:08] Paul McCarty: So I really am, um, reaching out to GitHub, we talked to a few people from GitHub last night, and saying, "This is a problem and we need to have a better, you know, incident response plan here from the GitHub side straight up."

[00:23:20] Jenn Gile: For sure. Well, uh, again, we're taking off for DEF CON here. We've got a workshop today, a panel later today, a talk tomorrow, and then we're out of here 'cause, uh, eight days in the desert is, uh, possibly eight days too many.

[00:23:34] Jenn Gile: It's a lot, but we've had a great week.

[00:23:37] Paul McCarty: Yeah, I love this week. Uh, I'm desiccated, but as I'm sure everybody else is. But, um, you know, just, uh, wanna say thanks so much for listening, and we've had a lot of people come up to us this week and say they really like the podcast, they really like the content that we put out there.

[00:23:52] Paul McCarty: We do this because we really love doing it. Jen and I are doing this right now because we really love doing this, and, um, it means a lot when people, you know, do that. So, uh, just wanna, you know, say to those people that, that, you know, came up and met us, thanks so much. It really makes us feel good. Thank you.

[00:24:06] Jenn Gile: Yeah. Plus one to that. Uh, it keeps us going, makes us feel like we're not just talking to each other here in a hotel lobby, um, you know, that we're doing some good. So with that said, uh, if you're in Vegas, hope you're having a great time. If you're not, it's okay. Uh, you know, you may have some FOMO, but there's lots going on, so we'll see you next time

[00:24:29] Ciao