logo

The OpenSourceMalware Show #20

ID: df8368a0-1475-508c-a842-85e22175a295

STIX ID: report--df8368a0-1475-508c-a842-85e22175a295

Feed Name: OpenSourceMalware Blog

Threat Score
80/100

Date Published: 2026-09-09

Date Updated: 2026-09-10

Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e

...
...

OpenSourceMalware episode #20 reports that a previously observed Mini Shai-Hulud payload resurfaced on npm after 111 days and that the PolinRider campaign continues to compromise thousands of GitHub repositories by abusing developer workflows (VS Code tasks, rewritten git history, poisoned config/files). Hosts discuss DPRK-linked activity, the scale and financial motive of these supply-chain attacks, gaps in GitHub/npm pre-publication scanning, detection limitations (hash/YARA shortcomings), and practical developer checks (inspect task files, suspicious fonts/configs) to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.