The OpenSourceMalware Show #19
ID: cb4cf046-174f-5e52-b9db-c112f6c9213e
STIX ID: report--cb4cf046-174f-5e52-b9db-c112f6c9213e
Feed Name: OpenSourceMalware Blog
Date Published: 2026-08-28
Date Updated: 2026-08-28
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
This podcast/blog episode reports the arrest of two alleged TeamPCP members and presents an operational briefing on DPRK-linked PolinRider: developers remain persistently infected by a RAT/info‑stealer that injects malicious payloads into repos and published packages, including a new NullReceiver payload and a particularly dangerous persistence technique that overwrites the npm CLI; the campaign has broadened target file types and continues to reinfect projects via collaborative workflows, prompting a call for disclosure and coordinated remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
