logo

The OpenSourceMalware Show #12

ID: 27b64963-24ac-575a-b51a-26274ac5cc9f

STIX ID: report--27b64963-24ac-575a-b51a-26274ac5cc9f

Feed Name: OpenSourceMalware Blog

Threat Score
82/100

Date Published: 2026-07-09

Date Updated: 2026-08-06

Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e

...
...

This episode transcript summarizes several active supply-chain and malware issues: PolinRider (attributed to North Korean/Lazarus) has automated repo‑hijacking that is now seeding packages into Go and PHP ecosystems; a cybersecurity vendor published multiple npm info‑stealers (later removed) apparently to manufacture data; the MeetingTV lawsuit alleges an AI-assisted false IOC publication by Koi/Palo Alto; and an interview with the Eclipse Foundation’s Open VSX head of security details rapid growth, pre-publish scanning, token management, detection of GlassWorm and sleeper extensions, and community-driven detection and remediation efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.