logo

The OpenSourceMalware Show #18

ID: 2bc744df-56d9-59e5-ba96-ca43ea0739d5

STIX ID: report--2bc744df-56d9-59e5-ba96-ca43ea0739d5

Feed Name: OpenSourceMalware Blog

Threat Score
85/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e

...
...

This episode summarizes multiple active supply-chain and typosquatting malware campaigns: a high-impact compromise of the popular Rust crate arrayref (and related packages) that introduced malicious build-time dependencies and has been linked by Wiz to DPRK infrastructure; the StubMaker campaign spreading identical 22 MB Rust/Go payloads across RubyGems and npm (and possibly PowerShell) via typosquats; a trend of attackers embedding compiled binaries (Rust/Go/C++) in packages; and a PolinRider reinfection wave now using NullReceiver for stealth — all indicating active, multi-ecosystem malware operations with persistence and cross-platform infection vectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.