The OpenSourceMalware Show #16
ID: 005ef7c0-87f8-531d-93ac-3b389bb7e95f
STIX ID: report--005ef7c0-87f8-531d-93ac-3b389bb7e95f
Feed Name: OpenSourceMalware Blog
Date Published: 2026-08-08
Date Updated: 2026-08-10
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
**Executive summary:** This blog/podcast episode reports three active supply‑chain and malware threats: a Keyv/cacheable npm worm (based on Mini Shai-Hulud) that infected ~400+ packages and searches developer machines/CI for credentials to exfiltrate; the WEL1DROPPER campaign which pushed >1,000 AI slopsquatted npm packages that execute on import and may be linked to Moika; and NullReceiver, a DPRK-linked C2 technique embedding C2 IPs in the recipient field of empty Ethereum transactions observed in at least 10 packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
