logo

The OpenSourceMalware Show #16

ID: 005ef7c0-87f8-531d-93ac-3b389bb7e95f

STIX ID: report--005ef7c0-87f8-531d-93ac-3b389bb7e95f

Feed Name: OpenSourceMalware Blog

Threat Score
88/100

Date Published: 2026-08-08

Date Updated: 2026-08-10

Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e

...
...

**Executive summary:** This blog/podcast episode reports three active supply‑chain and malware threats: a Keyv/cacheable npm worm (based on Mini Shai-Hulud) that infected ~400+ packages and searches developer machines/CI for credentials to exfiltrate; the WEL1DROPPER campaign which pushed >1,000 AI slopsquatted npm packages that execute on import and may be linked to Moika; and NullReceiver, a DPRK-linked C2 technique embedding C2 IPs in the recipient field of empty Ethereum transactions observed in at least 10 packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.