BLOG

The OpenSourceMalware Show #22

ShinyHunters attacks FBI, new WeaselBiscuit malware, Contagious Interview research, and dev FAQs

By cb482791-4ef1-4762-96ad-b0ca4bdd538e ·

The OpenSourceMalware Show #22

The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.

This week we talked about:

  • ShinyHunters vs. the FBI and Cl0p: ShinyHunters claims it stole data from an FBI jobs website through a PeopleSoft zero-day, and it is threatening to leak that data unless the FBI retracts a May FLASH tied to the Instructure Canvas breach. We cover why aging enterprise monoliths like PeopleSoft and WebLogic are such attractive targets. We also get into the group’s escalating public feud with ransomware crew Cl0p.

  • A correction on WhatsApp Baileys attacks: Malicious Baileys typosquats aren’t targeting WhatsApp payments, as we said last week. We explain what these packages actually do and how threat actors make money from them.

  • WeaselBiscuit: A new, stripped-down, self-contained malware family derived from BeaverTail and OtterCookie has turned up in 16 npm packages so far. We share the latest on attribution, what the malware is designed to steal, and why its minimal design helps it slip past detection.

  • FBI joint advisory on Contagious Interview: The FBI and international partners issued a joint warning about the DPRK IT workers scam and Contagious Interview (under the name WaterPlum), with figures on infected devices and stolen cryptocurrency. We discuss what the advisory leaves out. We also explain why its finding of shared infrastructure with the IT workers scam matters for researchers and defenders.

  • Atlassian’s Contagious Interview research: Atlassian published research on Contagious Interview activity across Bitbucket, GitLab, and GitHub, along with the actions it has taken on its own platform. We discuss what the report reveals about the campaign beyond GitHub and how platforms differ in responding to researcher reports.

  • Developer questions from TikTok: Our viral TikTok explainer on the VS Code tasks autorun technique drew a set of recurring questions from developers. We answer them, including “How this malware gets onto developer machines”, “Whether signed commits or switching editors would stop it”, “Why antivirus misses it”, and “How researchers know North Korea is behind it.”

Resources


[00:00:00] Jenn Gile: All right. It is Thursday, September 24th, and oh my goodness, we have so many things to talk about, Paul

[00:00:09] Paul McCarty: Our list is like War and Peace, I swear to God.

[00:00:13] Jenn Gile: It is. I went a little bit nuts. Um, so let’s- Did

[00:00:16] Paul McCarty: you see my notes as well, too?

[00:00:19] Jenn Gile: You put notes in. I’ll have to check on your notes, too. Um, so- They’re, they’re below

[00:00:22] Paul McCarty: under the 24th.

[00:00:23] Paul McCarty: Sorry.

ShinyHunters claims FBI hack

[00:00:24] Jenn Gile: Okay. I guess I’ll scroll a lot. Uh, oh, cool. I’ll move that up. So anyway, why don’t we start with the thing that’s big in the news. Um, we learned earlier this week that ShinyHunters, uh, is claiming, and it seems to be accurate, that they have, uh, hacked FBI records, uh, including an FBI jobs website.

[00:00:52] Jenn Gile: We’re hearing that they also may have, uh, gotten information on the people in the FBI whose job it is to do, you know, proactive hacking. Um, but the statement that they released on X is, uh, that they are not looking for money, that this is all about their credibility, and that this traces back to a flash that the FBI released back in May, um, when…

[00:01:24] Jenn Gile: I’m trying to remember which LMS this was, 'cause we talked about it on the show. There was a, a learning management system that was hacked and ransomed back in May. Remind me, was it Canvas?

[00:01:37] Paul McCarty: Yeah, it was Canvas, yeah.

[00:01:38] Jenn Gile: Yeah. So-

[00:01:39] Paul McCarty: Can- Canvas is the, is the brand name, and the company name is eludes me right now.

[00:01:43] Jenn Gile: Yeah, I don’t remember what the company name was. But essentially what they’re saying is they have all this data, that they’re giving the FBI one week to retract the flash, and if they do so, then they won’t release this data. Um, wild. Uh, thoughts?

[00:02:03] Paul McCarty: What, I mean, what can you say about this? Like, I’m gonna try really hard not to say any naughty words, because, like, it’s gonna be difficult.

[00:02:10] Paul McCarty: 'Cause the first thing I wanna say, let’s, at the top of this is, “Hey, ShinyHunters, you’re about… You’ve just effed around, and I think you’re gonna find out.” Right? Let’s just start with, with that. But it, here’s my second observation. Tell me you’re not an APT without telling me that you’re not an APT, which is like going and picking a fight with the FBI.

[00:02:35] Jenn Gile: With the FBI. It’s just nuts.

[00:02:36] Paul McCarty: And yeah, just like, and not, like, and this whole thing, it’s just so, it screams out, “I’m 17, and I don’t understand how the world works.” Right? That’s just what it screams out. And, um, yeah, I, I guess we’ll see where this ends up. But I mean, I guess, um, getting back to the, the heart of the, it, the company is called Instructure.

[00:02:55] Paul McCarty: Um, and they’re based in- Ah, yes. Thank

[00:02:57] Jenn Gile: you …

[00:02:57] Paul McCarty: yeah, they’re based in Salt Lake City, Utah. I actually have a contact that, that works there who did not… I reached out when they got hacked back in the… They, I didn’t hear anything back from them. But, um- Yeah, I mean, I think the thing is that they’ve popped, um, you know, they, they’ve popped the FBI job site.

[00:03:15] Paul McCarty: So it’s not like they per se-

[00:03:17] Jenn Gile: Hacked the FBI … compromised, but yeah Yeah, they, they hacked a system. I believe it was a Citrix or some- y- anyway, they exploited a, what sounds like a zero-day to get into personnel records. Which, don’t get me wrong, are serious, especially for an organization like the FBI. Yeah, I

[00:03:38] Paul McCarty: think they’re, I think they used what they’re claiming is a zero-day in PeopleSoft.

[00:03:44] Paul McCarty: Um, I… And, and I, I also wanna say, I wanna take the opportunity here. Like these… PeopleSoft is a great example of this. PeopleSoft, WebLogic, all these kind of older, crusty, monolithic monoliths are prime, I just can’t say this strongly enough, are prime- Oh, yeah … for this kind of thing.

[00:04:06] Jenn Gile: If you- They’re all full of really old components that are really hard to upgrade without breaking 50,000 things.

[00:04:17] Jenn Gile: Right. I mean, when I was working more in the DevOps space, you know, you saw a lot of the cloud migration and what’s gonna stay monolithic. And I mean, these are just really old systems, and it’s no surprise that there’s a vulnerability.

[00:04:33] Paul McCarty: Yeah, exactly. Um, and I think that’s where I was going, is that, you know, enterprise organizations, take note.

[00:04:40] Paul McCarty: You, you know, you spent years building up these crusty, you know, special snowflakes in these monoliths. And they’re public-facing. They all have portals. You know, whether it’s an HR platform or whether it’s, you know, your, your, your web platform, like W- WebLogic or something like that. You know, they’re connected to the internet, and so bad guys like ShinyHunters are gonna attack them.

[00:05:01] Paul McCarty: And these particular, um, platforms are prime, like, are just perfect for, you know, AI chaining bugs, right? So we’re gonna see a lot more of this. In fact, we saw, you know, this week, I know I’m jumping off topic already, but we’re, we saw the Australian government is saying that our Medicare system here was hacked as well.

[00:05:21] Paul McCarty: W- uh, s- calling it a hack is a little bit of a stretch, but was scraped in a way that the government doesn’t li- like it. But yeah, we’re just gonna h- we’re gonna see a lot more of this. Yeah. So getting back to ShinyHunters, um, I think they’ve bitten off more than they can chew. Uh, I think they’ve gotten cocky, that they, you know, like 17-year-old, 18-year-olds do, that they haven’t gotten popped.

[00:05:47] Paul McCarty: And now they’re gonna, they’re, they’re gonna FOPA.

[00:05:50] Jenn Gile: Yeah. You know, I’m getting a lot of- A lot of FOPA … in reading the ShinyHunters statement, I shared, uh, a link to it on X from, uh, the Dark Web Informer account. Um- Lots of vibes that sound a lot like the same type of, uh, attitude and phrasing that we heard from TeamPCP earlier in the year.

[00:06:12] Jenn Gile: You know, they take offense at being labeled Com kids. You know, they They’re, they’re drawing a lot of attention to themselves in a way that doesn’t seem wise. Um, so yeah. As you said- Yeah … mess around and find out. Um, you had a note here in our show notes, ShinyHunters versus Cl0p. Is that, uh, something you wanted- Yeah

[00:06:36] Jenn Gile: to get into?

ShinyHunters vs. Cl0p

[00:06:37] Paul McCarty: Yeah, really briefly. So basically last week, uh, let’s see what it said. No, no, this, earlier this week, um, Cl0p and Cl0p is a ransomware crew, a, a Russian, um, uh, aligned nation state aligned actor. Um, Cl0p and ShinyHunters had a short-lived collab earlier in the year, and they had a falling out.

[00:07:01] Paul McCarty: And, um, ShinyHunters has compromised, um, one of the Cl0p, um, websites, and beyond that, they’ve just, like, called them out repeatedly on Twitter. I refuse to call it anything but Twitter. Um, and they are dropping names. They’ve actually used, ShinyHunters has actually used names. So they’ve named several threat actors by last name and/or handle.

[00:07:26] Paul McCarty: I’m not gonna repeat those right here, but you know, you can go and find those yourself. And so, you know, it seems like they’re teasing real, real life IRL data, Jenn, like, you know, dropping people’s last names in there, um, uh, you know, Russian actors, uh, and, and just being super aggressive. And right now, Cl0p…

[00:07:49] Paul McCarty: And they’ve only made one or two statements in response to that, saying, “Hey, reach out to us. The email we tried using doesn’t work.” And then ShinyHunters came right back and said, “You idiot, you blah, blah, blah.” Just like super combative. So, you know, I mean, they obviously don’t think that Cl0p is, can come at them, which I don’t think is a smart thing to do.

[00:08:09] Paul McCarty: So it’s just, it’s so interesting to see. ShinyHunters, I suspect, has… I mean, they’re not a group, right? They’re like a, it’s like, it’s like when I was growing up in Michigan, like white kids pretending to be aligned with, like, street gangs, right? Like, you’re not really in a street gang. You’re just saying that you’re, you know, Latin Kings or whatever because you can say it.

[00:08:31] Paul McCarty: It doesn’t mean you actually are. So we’re gonna have a lot of that, but I think ShinyHunters is a real organization, you know, has, you know, their time is limited.

Correction on WhatsApp Baileys attacks

[00:08:38] Jenn Gile: Yeah. Okay. You also have in the notes, uh, something about, uh, WhatsApp Baileys attacks, and you said you need to make a correction. So, uh, lay it on us.

[00:08:49] Jenn Gile: What have you learned?

[00:08:50] Paul McCarty: Yeah. Yeah. Last week I said that the, there’s, so basically there’s just, oh, just constantly every day there’s these, these, uh, typosquats, um, for a, a library called Baileys. Um, and then there’s a, the, the WhiskeySockets and, you know, I, I understood what they did at some level, but I, I made the incorrect assumption that this was attacking WhatsApp payments, and it’s not.

[00:09:17] Paul McCarty: I took the time, I, I did what, I did what every ADHD kid does, which is I went and I was like, I said something, I was like, “I don’t know if that’s exactly true.” So I went and verified and, you know, went really deep. And basically what these libraries do, or sorry, what these attacks are, are, are trying to do is when you install this library, you think that you’re installing the real Baileys library, which allows you to connect to the WhatsApp, um, APIs and do legitimate stuff, right?

[00:09:42] Paul McCarty: So you’re building some app and you wanna integrate with WhatsApp, and you pull this Baileys library, this fake one, and you think… or malicious one, and you think that’s what it’s gonna do. Instead, what it does is it immediately has you follow a number of WhatsApp accounts, and then there’s all kinds of things that happen at this.

[00:09:56] Paul McCarty: But most of these attacks, Jenn, really are really simplistic. It’s just like you basically, without doing it yourself, you follow a bunch of things and, you know, they can s- they can send you to redirects and, you know, they can kind of find some ways to monetize your access. But in some cases I’ve also seen remote access.

[00:10:14] Paul McCarty: So they’re basically, when you install this, you become like a remote, you, you become a tool, a, um, a pawn of the WhatsApp based, um, C2 infrastructure. Um, but the vast majority of it is about followers. So I just wanted to make that correction. It’s not about payments.

[00:10:30] Jenn Gile: Okay. I’m gonna go ahead and share in the comments a link to our threat reports that are relevant to this in case anybody wants to check those out.

[00:10:38] Jenn Gile: Yeah. Uh, next we-

[00:10:39] Paul McCarty: I’ve been using the tag, I’ve been using… I’m sorry to interrupt. I’ve been using the tag Baileys.

WeaselBiscuit malware family

[00:10:44] Jenn Gile: Okay. Uh, next we released a blog, was it last week? I think it must have been last week, on a new malware family that you have discovered and documented and, uh, we teased last week on the show that we’ve named it WeaselBiscuit.

[00:11:03] Jenn Gile: Um, which again, I enjoy, uh, it’s fun. Still laughing

[00:11:08] Paul McCarty: about it.

[00:11:08] Jenn Gile: Yeah, it’s, it’s still fun. It’s a stripped down BeaverTail OtterCookie JavaScript self-contained malware. Um, it’s interesting because, uh, what, it doesn’t include a rat. Um, it’s a lot like thinner than a lot of things that we’ve seen. Um, so you said- Right

[00:11:26] Jenn Gile: you’ve observed it in 16 NPM packages so far. So it’s not like it’s- Um, taking off super fast in the way that we’ve seen, let’s say, the NullReceiver technique taking off, but-

[00:11:40] Paul McCarty: Right …

[00:11:40] Jenn Gile: uh, perhaps someone’s doing some experimentation right now. I think it’s a little bit interesting because with OtterCookie, what we saw was let’s, um, consolidate multiple different malware families into one so that this one malware family does more things.

[00:12:00] Jenn Gile: WeaselBiscuit goes the other way. It’s more simple. It has fewer stages. I think you said it only has three stages. Is that right?

[00:12:08] Paul McCarty: Correct.

[00:12:09] Jenn Gile: Yeah. What do you wanna share about it?

[00:12:12] Paul McCarty: Yeah, I think you mentioned just a second ago, I think the most important takeaway from WeaselBiscuit is that it’s just evidence of DPRK.

[00:12:20] Paul McCarty: Oh, and by the way, I, you know, we said it was, you know, looked like it was DPRK, but attribution was still a work in progress. I am 90% certain, certain this is DPRK and there’s, and there’s a couple reasons, you know, why we’ve attributed that and some of which we can’t talk about. But the reality is that I’m, you know, I’m pretty sure this is DPRK.

[00:12:44] Paul McCarty: So under that assumption, you know, I think this is evidence of DPRK just innovating and evolving and, you know, creating new stuff and just, you know, using the same tools we are. They’re figuring out what works and what doesn’t. And I think what they wanted here is they wanted just a, a quick, fast smash and grab, you know- Info stealer, which by the way, we know for a fact is working, right?

[00:13:11] Paul McCarty: We’re not gonna get into details, but we know for a fact this is working. This campaign has victims, um, and the focus on the keylogger and the, um, clipboard stealer is really important. They wanted something that focused on those so they could get access, ongoing access while the process is live, um, you know, to victims’ clipboards and their keystrokes and, and that’s exactly what they built here.

[00:13:40] Paul McCarty: It’s super stripped down, and as somebody pointed out on LinkedIn, really important point, it just skips a bunch of the things that, you know, tools look for, s- security tools like EDR and, and, and detection, mostly detection, you know, would look for. It doesn’t do those things. And so somebody asked me, “Why would they do something, why would they build something this stripped down?”

[00:13:59] Paul McCarty: Well, one, it’s fast. Two, it does what they want, and three, it bypasses a bunch of the detection we have. I mean, that’s a win for them.

[00:14:08] Jenn Gile: Yeah.

[00:14:08] Paul McCarty: Not for us.

FBI warning on Contagious Interview and DPRK IT workers

[00:14:09] Jenn Gile: That definitely makes a lot of sense. Um, our last two, three topics are all kind of, uh, falling under the same theme. Um, so last week the FBI issued a warning about Contagious Interview and the DPRK IT workers, um, scam.

[00:14:30] Jenn Gile: Um, it is under the code name WaterPlum. I did a little digging to see does that mean something. It’s just a code name. For whatever reason, that’s what they’re using to describe Contagious Interview. It’s not like it’s a different campaign. It’s not like it’s being tracked differently. Um, it’s a joint warning between the United States as well as agencies from Japan, Australia, Europe, includes Germany.

[00:15:01] Jenn Gile: So, uh, lots of governments got together. As these warnings tend to be, it’s fairly simple. Um, it- You know, covers, I would say, things that people who’ve been looking at this space probably already know. But it’s a signal that, um, you know, the governments are taking this seriously, that this is a known problem.

[00:15:25] Jenn Gile: Um, I took down a couple of things that I think are worth calling out from this. Um, first, you know, they talk about Contagious Interview broadly targeting, um, or pretending to be from legitimate AI companies, crypto companies, and, uh, NFT companies. And I didn’t even really know NFT companies were still around, but apparently they are.

[00:15:49] Jenn Gile: Um, I don’t play in that space. Um, but, you know, understandably, they’re pretending to be from those types of employers because those types of employers attract certain types of profiles of people. And so the, um, targets that they’re going after, no surprise here, uh, individual web developers, engineers, and people who are specializing in cryptocurrency, blockchain, and Web3 technologies.

[00:16:15] Jenn Gile: Um, they have some interesting numbers in the paper. They said that they’ve attributed, uh, infection to, uh, Contagious Interview, uh, for thirty thousand devices in more than a hundred companies… Countries, sorry. So thirty thousand devices infected in more than a hundred countries. That’s a lot. Uh, they say that they have, uh, been able to track the exfiltrated funds and credentials are coming from over seven thousand cryptocurrency wallets.

[00:16:49] Jenn Gile: And here was one thing that surprised me. The figure in terms of cryptocurrency assets stolen, in my opinion, sounds really low. Uh, they’re saying, uh, it’s the equivalent of about, uh, ten point seven million dollars of stolen crypto. I mean, we’ve seen numbers in the billions, so it’s a little surprising to me that it was, uh, in the millions, but You know, it’s a, a very basic report.

[00:17:20] Jenn Gile: It may not be all time figures. Hard to say, like, what the, the asterisks are. Um, Paul, it sounds like you wanna jump in there for a second.

[00:17:30] Paul McCarty: Yeah, I just wanna, uh, uh… 'Cause like you, I saw them and I thought, “What are they, what are these guys on?” Well, first, you know, they’re missing this document. While, you know, I think you and I both felt like it’s awesome that, that they’ve come out with this, right?

[00:17:43] Paul McCarty: It, it kind of helps lend legitimacy to some of the enterprise customers that we talk to that are like, “Oh, what is DPRK doing?” Well, hey, here’s FBI warning you about this thing you probably don’t, haven’t thought about. That aside, um, I think that the $10.71 million thing is just kind of, you know, I don’t know, them being clueless.

[00:18:02] Paul McCarty: Not clueless, that’s not the right word, but just, you know, being kinda kooky, right? Because we know for a fact last year alone, Bybit, one single attack was a billion dollars.

[00:18:15] Jenn Gile: Right, but that wasn’t Contagious Interview. They’re talking explicitly about Contagious Interview here.

[00:18:20] Paul McCarty: Yeah, agreed. But I also don’t…

[00:18:22] Paul McCarty: Because they don’t… You and I both know, they ha- they’re not talking about PolinRider, and PolinRider is part of the Contagious Interview, you know, e- evolution of what Contagious Interview has become. And so my reason to bringing up Bybit is just to say, you know, I don’t think they’re really looking at the whole scope of this attack surface itself.

[00:18:41] Paul McCarty: But anyhow, that’s just them- Yeah … being a little bit kooky.

[00:18:43] Jenn Gile: Well, uh, one thing that I found worth calling out from the paper that was, I wouldn’t say new to me, but I don’t hear people talking about it, is they said that they have found infrastructure overlap between Contagious Interview actors and North Korean IT workers.

[00:19:02] Jenn Gile: So they said that they’re using the same IP addresses when they’re accessing laptop farms, uh, using the same cloud sourcing services, and applying for positions at the Japanese cryptocurrency exchange. Um, so I think we kind of knew that these groups were coming together. Uh, not a huge surprise that there would be- Right

[00:19:25] Jenn Gile: something in common with the same IP addresses. It makes me ask, what else are they reusing? Uh, it’s an area that we were already looking at, but I think that’s a question all researchers should be asking right now is, is what’s shared.

[00:19:40] Paul McCarty: Well, yeah. And on that point, I think, w- first, I think that egress, they…

[00:19:44] Paul McCarty: Because they like to use Astrill VPN, the egress I- IPs from… There’s only so many IPs that Astrill has total, right? And those number, those IP addresses are well-defined, so you can go look 'em up, so right? They’re gonna reuse those. If they continue to use Astrill, they’ll, they’ll reuse those. Um, uh, second, um, the, um- the overlap between IT workers and the stuff that you and I care about is interesting to you and I.

[00:20:12] Paul McCarty: But w- over the last few weeks, we’ve definitely seen overlap now between ClickFix and what ClickFix is becoming, and all these other variants, right? And classic Contagious Interview/PolinRider. There are, you know, some of the C2 infrastructure are the same. Some of the p- the payloads are literally exactly the same.

[00:20:33] Paul McCarty: So, um, you know, the… I, I think something that we heard generally at, at UE is that DPRK is starting, like these different groups that used to be kind of separate and isolated by design are starting to work more together, like the, uh, BlueVoyant kind of, you know. So because of that, I think it’s not surprising that we’re seeing now more of the stuff kind of overlap, which is good for us because when we identify an indicator, right, that indicator might be used in ClickFix and it might be used in Contagious Interview and VS Code stuff.

[00:21:05] Paul McCarty: So, um, you know, it expands the reach of our, what we can see.

[00:21:08] Jenn Gile: Yeah, and I mean to the, to keep following that train of thought, um, shutting down a piece of infrastructure can have more of a blast radius in terms of, you know, disabling activity if they’re sharing infrastructure.

[00:21:26] Paul McCarty: That’s a, that’s a really good point, Jenn.

[00:21:28] Paul McCarty: Good job for bringing that up. That’s a really good point. When we… Yeah, well I’m, you said it well, I’m not gonna… Done.

Atlassian report on Contagious Interview

[00:21:35] Jenn Gile: So let’s, let’s start tearing stuff down. Okay. Uh, another report came out on Contagious Interview. We’re on a roll. Uh- Mm-hmm … a friend of mine posted this on LinkedIn the other day. They work at Atlassian, they’ve been working on this.

[00:21:47] Jenn Gile: Um, so Atlassian, uh, released a report of their own internal research on Contagious Interview. You might ask, why would Atlassian be looking at this? Well, Atlassian owns Bitbucket, which is a competitor to GitHub. Um, I think it’s a really nice piece of research. I’m going to copy, uh, the link into the comments here, and what I’ll say is you can read kind of a summarized blog version, and then you can download their PDF.

[00:22:15] Jenn Gile: The PDF’s something like 40 pages. I think it’s definitely worth looking at both, not just the blog. Um, but I wanna call this out for a couple reasons, um, in a positive way. So we get asked a lot every time we’re out in the community, “Why isn’t GitHub doing anything about this?” So it’s really interesting to hear from another vendor, another SCM platform, uh, Atlassian looked at GitHub, GitLab, and Bitbucket.

[00:22:44] Jenn Gile: So they were looking at multiple SCMs. Um, gosh, there’s lots of ways to take my opinions on this. First of all, Atlassian is clearly doing something about it, which I think is fantastic. You know, they said in their paper that they’re actively working on ways to detect and respond to, uh, attempts to abuse their platform.

[00:23:06] Jenn Gile: So they claim they’ve taken down hundreds of Contagious Interview- repositories and accounts, um, that they’re continuously improving their detections, they’re improving their, um, threat hunting, and they’ve made it easier to report, um, abusive content on Bitbucket. So I think that’s nothing but good. Like, amazing for them, amazing for Bitbucket users.

[00:23:30] Jenn Gile: Um, I think the other part that’s worth talking about is we’ve really only talked about PolinRider and Contagious Interview on GitHub, and the reason we do that is because it’s just so easy to find it. Like, not only are the repos public, but you can search and you can just see anything there. Um, you know, that doesn’t mean Bitbucket and GitLab aren’t seeing Contagious Interview, and what this report that they shared, uh, proves is that yes, in fact, these other SCMs do see it also.

[00:24:01] Jenn Gile: So you’re not safe if you’re not using GitHub. I’m sorry, you’re not any safer, if that makes sense. Um, so they are in those other SCMs, but, uh, you know, it’s a little bit more hidden. And then the last thing that I would add, uh, reading between the lines on the report, because they don’t talk about the PolinRider malware, they’re really focused on, uh, the Contagious Interview repositories, but they’ve talked about victims infecting other people, and what that sounds like to me is they certainly have seen some indicators that PolinRider is in Bitbucket as well as, you know, potentially other places

[00:24:46] Paul McCarty: Yeah, agreed.

[00:24:47] Paul McCarty: Um, uh, not surprising that PolinRider is gonna be in all those places, because the reality is that, you know, in that, that text that I shared with you earlier today, the… You know, all we’ve been seeing and reporting on are public repos with PolinRider.

[00:25:03] Jenn Gile: Exactly.

[00:25:04] Paul McCarty: We can only imagine the sheer number, you know, outweighing the public stuff by factors of who knows what, of private repos.

[00:25:14] Paul McCarty: Because when PolinRider goes and writes their payload and stuff, they don’t go, “Oh, let me only write it into the public ones.” They write it into all of them. And, you know, everybody’s gonna have way more private repos than they’ve got public. So to that point right there, um, you know, I’m not surprising that it’s gonna be in Bitbucket and everywhere else.

[00:25:31] Paul McCarty: Now, a couple things I do wanna say. First, I love the article as well. The, sorry, the, the blog post from Atlassian. I really… I, I like that they’ve always been a little bit more responsive and, you know, I, I like their behavior better. But, but also too, the problem is much smaller in Bitbucket.

[00:25:47] Jenn Gile: Oh, for sure.

[00:25:49] Jenn Gile: You know? So- It doesn’t have the same blast potential that GitHub does. Right. You know, both GitLab and Bitbucket aren’t built on, uh, like a real PLG type of business model- Yeah … the way that GitLab, uh, GitHub is.

[00:26:07] Paul McCarty: Well, yeah, and the, oh, the specifically the public open source projects, you know, obviously at, you know, you’re speaking to that point, like 99.9% of them, some ridiculously huge number is, you know, on GitHub.

[00:26:19] Paul McCarty: And so we just get a lot more visibility into GitHub. And, you know, frankly, like they, they, the number of GitHub repos outweighs the other two by factors of who knows what again. Mm-hmm. I don’t have ma- I don’t have the math in front of me. But to the last point is that, yeah, the volume’s a lot higher in GitHub, but also too, when I find something in Bitbucket, I can reach out to my network in Atlassian and they work on it.

[00:26:40] Paul McCarty: Like, they immediately, you know, action it. And it’s just so frustrating right now, GitHub, I’m talking to you again, that I can only, I can only report these as malware, these repos, individually. Now, my little hack is that I use one individual repo at, to report it, but then I put a list of like 1000 in there, which I know you love, but you’re not making it easy for me to report these things that are happening in the thousands because you have no bulk API, there’s no bulk process.

[00:27:07] Paul McCarty: You’ve chosen to make this very difficult for me to disclose and so, hey, suck it. Um, but, you know, Atlassian, they action it, and that’s really important. And I wanna make a call. I didn’t, I didn’t ask my friends at, at As- Atlassian if I could drop their name, so I won’t. But I do wanna speak to them, say thank you that, you know, for being responsive.

[00:27:25] Paul McCarty: I wish I had one quarter of that from the, you know, from GitHub. Hell, I’d be happy with one tenth of that from GitHub

Developer questions from TikTok

[00:27:32] Jenn Gile: Amen. Okay, the last topic is a long one. Um- This is all you,

[00:27:39] Paul McCarty: too.

[00:27:40] Jenn Gile: So this is all me. I made the debatable decision, uh, as the person who runs our social media to open a TikTok account for OpenSourceMalware, and I did this a while ago.

[00:27:52] Jenn Gile: I did it around the same time we started podcasting. You’re welcome,

[00:27:55] Paul McCarty: China.

[00:27:56] Jenn Gile: Yeah, well, you know- … they’re not getting anything that we’re not already streaming onto- Right … the internet, so it’s like, whatever. True. Uh, and if I can reach more people and educate more people, then I’m good with it. Now, the irony here is I won’t use X, so call it what it is.

[00:28:14] Jenn Gile: But anyway, I, you know, had just been kind of posting snippets from our podcast on TikTok and then, uh, one or two weeks ago I decided, “You know, I’m gonna record a short tutorial that explains how the tasks, uh, auto-run function works with a fake font file.” And so I picked a random repository, recorded, you know, a little explainer.

[00:28:41] Jenn Gile: Uh, anybody who’s worked in tech, uh, who’s done explainers, like, this is pretty standard stuff where you’re like, “Here’s what this thing does.” So I talked about the task file, I talked about, uh, you know, the fake font file, I talked about the obfuscated JavaScript. I tossed it up there and, um, it went viral, which I was not expecting.

[00:29:03] Jenn Gile: As of right now it has over 300,000 views. Uh, it has thousands of likes and comments. And yeah, uh, unexpected, but the reason I wanna talk about it is because as I was scrolling through the comments, uh, and ignoring the trash fire that was in some of them, I, I saw some really clear themes. And given that the audience that was engaging with this video included a lot of very obviously developer-type people, I thought that these themes would be worth us having a conversation about here, um, because it kind of shows in many ways a lack of understanding of how malware is getting into open source and how developers are consuming it.

[00:29:49] Jenn Gile: And so I thought kind of talking about this, um, you know, might, might be helpful. So I’m not gonna take these necessarily in order, 'cause there’s what?

[00:30:01] Jenn Gile: I don’t know, eight or nine of them. Um, some of them we’ll touch on really briefly, and some of them I think we should talk more about. So one area that I saw a lot of questions about was, “How does this get on my machine in the first place?” Uh, there was not a lot of understanding that normal development behavior is what exposes developers to PolinRider.

[00:30:30] Jenn Gile: And I don’t think there’s, like, a whole lot more to say about that, but it was like, “Great, but, like, how do I even ingest this?” So I guess, Paul, you know, that came as a little bit of a surprise to me. I would have expected going in that people would have understood that forking a repo is how you get this kind of stuff.

[00:30:52] Jenn Gile: What do you think?

[00:30:54] Paul McCarty: Yeah, I mean, I think it’s kinda like if, you know, you show up to a group of religious purists and you say, “Hey, this other thing is true,” and it doesn’t align with their worldview. They’re like, “Well, that’s not possible.” And so my crazy Paul metaphor here is that, you know, I think developers aren’t, many software engineers aren’t aware of the fact that the source code itself can be dangerous, right?

[00:31:19] Paul McCarty: They have to think there’s gotta be, like, a binary. They’re, like, you know, this kind of, like, gets us back to this, all this antivirus history that we have and about how it works, and that s- it’s kind of influencing their thinking. So particularly when combined with the fact that they don’t understand that VS Code, which, you know, 76% of them have on their machine and they’re using daily, is helping this campaign.

[00:31:41] Paul McCarty: So Microsoft, DPRK sends its thanks for allowing auto, you know, tasks to run. Again, the, the, the not understanding those two things, Jenn, I think is at the heart of this, and it really does, and it really… And I’ve seen this for 30 years, you know, trying to work with software engineers around security principles.

[00:32:01] Paul McCarty: When you’re basically saying to them, “Something that you’re doing is insecure,” the natural inclination is to respond back with, with, um, kind of anger and combat. It’s like, “No, it’s not.” You know? And- I

[00:32:12] Jenn Gile: wouldn’t describe this as anger. I would describe it as genuine, like, “I don’t get it. How does this work?”

[00:32:18] Paul McCarty: Well, yeah. So that’s a good point. I guess what I’m saying is that they’re respond- responding back like that, “No, that’s not possible. How, how does that work?” Because you’re calling into question some of these fundamental things that they don’t understand, and they’re used to being… I’ve said this about software engineers for a long, long, for, you know, many, many years, which they create stuff out of nothing, and it’s magic.

[00:32:38] Paul McCarty: It is the equivalent of magic in the modern world, and they’re so used to being, “Ah,” which is great, you know. It’s awesome. We create things out of nothing, but when you call into question something they don’t understand that’s fundamental to how they operate, that’s, you know, I think that’s the problem right there.

[00:32:54] Paul McCarty: Interesting. Well- And so many of them just

Wouldn’t signed commits stop this

[00:32:55] Jenn Gile: don’t understand … I would say there were definitely people in the comments who did understand, but where their understanding stopped was the human behavior part. And so, uh, I would group this into wouldn’t branch protection or sign commits stop this? Uh- Mm-hmm

[00:33:14] Jenn Gile: wouldn’t disabling tasks autorun stop this? Wouldn’t, um, not clicking I trust this, you know, repository stop this? And they’re right. It, all of those things would stop this. But- Uh-

[00:33:30] Paul McCarty: Maybe …

[00:33:30] Jenn Gile: bear with me, bear with me.

[00:33:32] Paul McCarty: Okay.

[00:33:33] Jenn Gile: When your default is you have to opt in to those kind of things, it means that the vast majority will not have opted in, and that’s the way that both GitHub and VS Code have designed their tools, is many of the things that would Reduce your exposure are things you have to know what it does, know how to turn it on.

[00:34:03] Jenn Gile: Right. So I’m not gonna, like, debate, like, would signed commits totally stop this? But the point is more when you require these things to be opt-in, that’s what’s making it more dangerous, and I think it’s, um, irresponsible of people to say, uh, “Oh, well then it’s, you know, just stupid humans.” You know, we- we’re all…

[00:34:31] Jenn Gile: This is, this is human psychology. We’re all stupid, I’m sorry.

[00:34:34] Paul McCarty: Yeah. Our brain is, our brain has been wired to take the easy course whenever we can, right? And- 'Cause it saves us time …

[00:34:41] Jenn Gile: our brain is wired for trust, which is crazy. But our brain- Right? … is just wi- Like, if, if you are shown something and asked do you trust this, our brains are wired to say, “Oh, yeah, I do.”

[00:34:52] Paul McCarty: Right? When, when all the data, all the experience behind that shows that we shouldn’t trust it, our brain goes, “Okay, we will.”

[00:35:01] Jenn Gile: Yeah.

[00:35:01] Paul McCarty: I am… I, so hey, Jenn, I’m gonna be spicy here, as I like to do, and say in my experience when somebody pushes back against me, “Well, wouldn’t signed commits fix this?” And I say to them, “Well, do you sign your commits?”

[00:35:15] Paul McCarty: They will often say, “Well, sometimes.”

[00:35:17] Jenn Gile: Yeah.

[00:35:17] Paul McCarty: Right? On one of my machines. So they’re not even doing it, so they’re, they’re coming back with a thing to, to prove that what we’re saying is

[00:35:24] Jenn Gile: incorrect. Oh, absolutely. They’re probably not doing it anyway.

[00:35:27] Paul McCarty: Well, and here’s the thing is you very correctly said in your notes, and I think in your, your blog post, that, you know, just signing your commits, the, the bad guy, that’s on your machine.

[00:35:36] Paul McCarty: That just automatically happens. Like, the bad guy, DPRK has persistence on the w- on the developer’s workstation, and so they just push and it rides the successful commit in. Unless you use an SSH key and you wrap a password, which many people don’t even know you can do, and they won’t want… They don’t wanna do it because every time they do, uh, they commit, it’s gonna say, “Hey, can you add your password?”

[00:36:00] Paul McCarty: And they’re like, “I’m sick of typing my password.” But guess what? I do that. Why? Because that’s the only way for me to know that somebody on my machine cannot push code as Paul. Boom. So I accept the fact that there’s a little bit of latency and a little bit of hassle because of this, and humans need to do that more often and they don’t, and that’s a problem.

Commit hashes and fake Git history

[00:36:20] Jenn Gile: Yeah. Well, I posted a second related video because I realized there were a lot of questions about, like, the Git history itself, and so I posted a short video talking about how, uh, DPRK is, you know, force pushing and faking Git commit history. And, uh, there was a very, um- Active sub-thread about commit hashes, and wouldn’t commit hashes reveal the fake history?

[00:36:48] Jenn Gile: And the, the easy q- answer, the short answer is yes. But like what you said with signed commits, this requires you to look at them, this requires you to save them, this requires someone to have a copy of it. Um, I don’t think there’s a lot more to say there on, like, yeah, these are all things that are true.

[00:37:10] Jenn Gile: But if they’re not- Yeah … part of your process, if they’re not, you know, codified into how you write code, then they’re not gonna help you.

[00:37:20] Paul McCarty: This is, this falls squarely in that bucket I was talking about of things like the, “Well, wouldn’t this w- fix it?” I’m like, “Well, do you, do you track these?” “Well, no.” "Okay, then please don’t mention it to me again.

[00:37:30] Paul McCarty: Thank you."

Vim vs. VS Code

[00:37:30] Jenn Gile: Yeah. Now, a lot of people replied and were like, “Well, this is why I use Vim,” which is an alternative to VS Code. Um, and

[00:37:38] Paul McCarty: I’m gonna say- Which I, which I love 'cause I’m an old guy.

[00:37:43] Jenn Gile: Well, I mean- And I use Vim … they’re not wrong. Um, you know, if you’re using something that doesn’t use tasks autorun by default, then sure, you’re gonna be safe from that particular attack vector. Exactly. I think using Vim in itself is not like, oh, Vim is more secure. It’s more like, oh, it’s not being targeted and it’s not configured that way.

[00:38:06] Jenn Gile: If you configured VS Code in a smarter way, it’s, it’s not necessarily worse.

[00:38:14] Paul McCarty: Yeah. It’s like saying that, you know, a surface-to-air missile, like if I fly my jet, the surface-to-air missile won’t get me. So instead, I’m gonna drive a car because a surface-to- … Like, you know, the jet is way better. And-

[00:38:23] Jenn Gile: Yeah …

[00:38:23] Paul McCarty: as much as I, I love Vim, I don’t know if VS Code is better than Vim, but for the purposes of my metaphor, I’m gonna continue with, to say, you know, it’s, it’s just not the right thing.

[00:38:33] Paul McCarty: Anyhow, um, I think to your point, like one of the ways that DPRK was, was using, uh, to infect people was, was with Git hooks. And in using Vim, everybody uses Git, right? And so you’re gonna get infected no matter what IDE you’re using. So it’s not really, you know, about Vim-

[00:38:52] Jenn Gile: Well, sure … versus VS Code. Like, I was talking very specifically about the tasks thing.

[00:38:56] Jenn Gile: So like- Un- …

[00:38:56] Paul McCarty: let’s

[00:38:57] Jenn Gile: not conflate the two.

[00:38:58] Paul McCarty: Under… Yeah, yeah. Yeah, it’s true, but I’m just saying that like, you know, people saying that using one, you know, there’s other attacks that DPRK has that it’s gonna affect that one, so-

[00:39:07] Jenn Gile: Yeah …

Why antivirus doesn’t catch this

[00:39:08] Paul McCarty: it’s gonna affect

[00:39:08] Jenn Gile: the other. Now, I do wanna, um, talk about something that I’m sure a lot of listeners do have questions about, in the same way people in the comments did on this video, and that was, um, why doesn’t antivirus catch this?

[00:39:22] Jenn Gile: And I mean, gosh, I wish antivirus was capable of understanding what code is doing. But the reason your antivirus will not catch a PolinRider, whether it’s the tasks JSON, uh, you know, autorun stuff, whether it’s a config file with obfuscated code, whether it’s a Git hook, is because these are like normal development things that have bad stuff in them.

[00:39:53] Jenn Gile: So it’s not like, uh, you know, it’s not a signal that it can look for, in the same way that EDR can’t look for it, because this is weaponizing the normal way that people write code

[00:40:13] Paul McCarty: Yeah. Uh-oh, my internet’s getting… I wonder if my internet’s getting crappy. Um, I think that there are some, there are some EDR or AV engines that, you know, Kaspersky is a good example of this, that is, is actively hashing individual JavaScript payload files, which is- Hmm, that’s a lot … you know, the closest, which is, that’s the closest this gets, right?

[00:40:37] Paul McCarty: And that’s not a particularly effective way of detecting this stuff. So, um, you know, I do see Kaspersky identifying things in, for example, VirusTotal when other, you know, platforms, CrowdStrike and SentinelOne haven’t. But that aside, I’m sorry, friends, for a whole bunch of reasons that we don’t have time to talk about today, um, you know, EDR and AV are not gonna be helping you here.

[00:41:00] Paul McCarty: The, all this stuff looks like normal, standard Python or J- or, or JavaScript processes on your machine. That’s not what EDR or AV is built to detect, so, you know, it’s like s- it’s just not built for that.

How do you know it’s North Korea

[00:41:14] Jenn Gile: All right, so the last thing I wanna talk about, and, uh, this is a genuinely difficult question, um- I found myself, as I was thinking about this question, uh, you know, kinda like the nesting dolls, uh, metaphor.

[00:41:33] Jenn Gile: Mm-hmm. Th- so the hor- heart of the question is, how do you know that this is North Korea? And my knee-jerk reaction was, well, if you look at the obfuscated code, and, you know, you look at the malware that’s in it and the, uh, infrastructure that’s in it, that’s linked to North Korea. But I think a fair question that was asked is, right, but how do you know that that belongs to North Korea?

[00:42:04] Jenn Gile: So Paul, you’ve been looking at this for a couple years. Mm. How… Uh, this is not a question I know how to answer, so I genuinely wanna know, like, how would you tell people that the industry has definitively said, “We know North Korea is behind this”?

[00:42:23] Paul McCarty: Man, that’s a whole episode right there, but, um, I will try to simplify for the purposes of the conversation.

[00:42:31] Paul McCarty: And just to be clear, I’m not an expert on attribution, right? I think the first thing we need to realize is that attribution in a kind of binary-based payload, the kind of traditional historical world, looks different. And so I can understand how some people would say, “Well, over here in this highly iterative world, how are you able to attribute it to DPRK?”

[00:42:53] Paul McCarty: Um, and the reality is it’s, it’s, you know, it’s not really a science. There’s, you know, some guessing and some, you know, because it’s moving fast, you, you have to make guesses where you, you can’t necessarily, um, you know, attribute to a specific IP or what have you. But, uh, sometimes it’s really easy. So for example, you know, there were indicators, URLs and IP addresses that were used in kind of classic Contagious Interview, um, campaigns that were then reused in the early stages of PolinRider, for example, and TasksJacker.

[00:43:23] Jenn Gile: And so we ident- Well, I think maybe this comes back to what we talked about m- half an hour ago about shared infrastructure between the IT workers and Contagious- Right … Interview campaign. At some point, somewhere back in the thread of history, someone was able to attribute a piece of infrastructure or some kind of a signal to North Korea.

[00:43:49] Jenn Gile: And I think with the IT workers it’s easier because we have things like language as a tell, uh, locations as a tell. Uh, but the IT worker scam hasn’t been around forever, so yeah, I mean, the, the- Answer that’s not an answer is at some point someone had an indicator that they connected to North Korea, right?

[00:44:09] Paul McCarty: Yeah. I mean, like, s- the, the, the large organizations, you know, uh, will attribute some of these components and then, you know, you base your attribution on the fact that something you found has a shared piece of infrastructure there. But let’s be very clear, like, the, the, a l- you know, a lot of the, most of the DPRK stuff that we look at does not have a shared indicator, URL, IP address, or otherwise with existing known attributed indicators.

[00:44:34] Paul McCarty: Instead, and this is really important, what happens is if you take the time, like OpenSourceMalware does, to deconstruct the whole thing, what happens is you end up with a payload and a structure and a format and a pattern that matches other known, you know, patterns, right? And that’s where, like, if, if we see that it’s delivering OtterCookie, if we see that it’s delivering some of these other kind of components, well, guess what?

[00:44:58] Paul McCarty: We use that to connect. Why? Because there’s no way that you can attribute all these, these indicators because there’s just too many of them. DPRK is creating hundreds of these things a day, and nobody at Palo Alto or CrowdStrike or any of these organizations are attributing all those indicators. Instead, you look for the patterns and then you say, "Hey, this is exactly like all these other ones.

[00:45:21] Paul McCarty: Therefore, we’re gonna say this is DPRK." Is it a science? No, not claiming it’s a science, but, you know, it works, and that’s what we’ve got.

[00:45:29] Jenn Gile: Yeah. All right. Well, uh, thank you for taking on the hard question. Um, if you wanna give us a follow on TikTok, go for it. It’s entertaining, if nothing else. Uh, and with that- I’m

[00:45:41] Paul McCarty: not there.

[00:45:42] Paul McCarty: Jenn will see it, but I won’t.

[00:45:43] Jenn Gile: Yeah, yeah, yeah. Uh, so Paul, you’re in Canberra for BSides Canberra. Enjoy the conference. Mm-hmm. Uh, I hope your training goes amazing. I’m sure it will. Thank you. Um, remind me, this is the biggest BSides in Canberra? Or I’m sorry, obviously, in Australia.

[00:46:00] Paul McCarty: Oh, it’s a b- it’s definitely the biggest in Australia.

[00:46:01] Paul McCarty: It is, I think… Well, no, it is. It’s officially the biggest in the world. Yeah. Last year we had 38 pe- 3,800 people at Canberra BSides, which is bigger than both BSides San Francisco and Las Vegas. Therefore, it makes it, as far as I know, unless somebody else comes out with a bigger one, it’s the biggest one I know about.

[00:46:19] Jenn Gile: Exciting. I’m gonna give one shout-out. Uh, the BSides Seattle conference just opened the CFP. Uh, it’s gonna be closing here in about six weeks. Uh, I work with the BSides Seattle conference. I am not in charge of the CFP, so if you don’t like it, don’t come yell at me. But please- … apply for it. Uh, I think it’s the best BSides.

[00:46:42] Jenn Gile: Uh, come find me.

[00:46:44] Paul McCarty: Not the biggest, but the best according to Jenn. Yeah. Um, I wish, I wish I could put a paper in for the CFP and, and come and join y’all, but, uh, you know, that’s a big trip. It’s a

[00:46:54] Jenn Gile: lot of travel.

[00:46:56] Paul McCarty: That’s a lot of travel.

[00:46:57] Jenn Gile: All right, everyone, have a great one. Thanks for sticking around for this extra long episode.

[00:47:01] Jenn Gile: Uh, maybe we’ll be back to our regular length next week.

[00:47:06] Paul McCarty: Well, when we got stuff to talk about, we got stuff to talk about, Jenn. I expect- Thanks everybody for listening. Appreciate it. Bye. See you. Bye.