The OpenSourceMalware Show #12
ID: 27b64963-24ac-575a-b51a-26274ac5cc9f
STIX ID: report--27b64963-24ac-575a-b51a-26274ac5cc9f
Feed Name: OpenSourceMalware Blog
Date Published: 2026-07-09
Date Updated: 2026-08-06
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
This episode transcript summarizes several active supply-chain and malware issues: PolinRider (attributed to North Korean/Lazarus) has automated repo‑hijacking that is now seeding packages into Go and PHP ecosystems; a cybersecurity vendor published multiple npm info‑stealers (later removed) apparently to manufacture data; the MeetingTV lawsuit alleges an AI-assisted false IOC publication by Koi/Palo Alto; and an interview with the Eclipse Foundation’s Open VSX head of security details rapid growth, pre-publish scanning, token management, detection of GlassWorm and sleeper extensions, and community-driven detection and remediation efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
