The OpenSourceMalware Show #14
ID: 48f80cdf-985f-5b02-bd33-02041645de7c
STIX ID: report--48f80cdf-985f-5b02-bd33-02041645de7c
Feed Name: OpenSourceMalware Blog
Date Published: 2026-07-23
Date Updated: 2026-07-24
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
Weekly OpenSourceMalware roundup covering a Hugging Face breach (with contested OpenAI involvement), AgentBaiting — thousands of malicious GitHub repositories targeting AI agents and embedding natural-language instructions, a wave of RubyGems packages resembling the GemStuffer exfiltration campaign plus a long-standing RubyGems API-key caching leak, CrashStealer — a macOS infostealer with additional RAT tracks, and research linking ChainVeil/ViteVenom to DPRK PolinRider via shared byte-for-byte IoCs; the episode highlights supply-chain risks, novel exfiltration channels (gems, blockchain memo fields), and rapidly evolving attacker TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
