The OpenSourceMalware Show #21
ID: ed54c068-72f8-5eef-80cd-a71f39579662
STIX ID: report--ed54c068-72f8-5eef-80cd-a71f39579662
Feed Name: OpenSourceMalware Blog
Date Published: 2026-09-17
Date Updated: 2026-09-17
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
This episode of the OpenSourceMalware show reviews several active threats: the GemStuffer RubyGems campaign (thousands of spammy packages, suspected OpenAI agent involvement), a Truffle Security finding of a CDN misconfiguration that could leak API keys enabling package uploads, PyPI typosquats from a 'lurves-agent' campaign that deliver a small info-stealer and include prompt-injection, and a typosquatted claude-desktop.com site distributing a signed macOS DMG with malware; it also highlights PolinRider (DPRK) supply-chain activity and urges treating AI agents and signed installers with caution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
