logo

The OpenSourceMalware Show #21

ID: ed54c068-72f8-5eef-80cd-a71f39579662

STIX ID: report--ed54c068-72f8-5eef-80cd-a71f39579662

Feed Name: OpenSourceMalware Blog

Threat Score
78/100

Date Published: 2026-09-17

Date Updated: 2026-09-17

Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e

...
...

This episode of the OpenSourceMalware show reviews several active threats: the GemStuffer RubyGems campaign (thousands of spammy packages, suspected OpenAI agent involvement), a Truffle Security finding of a CDN misconfiguration that could leak API keys enabling package uploads, PyPI typosquats from a 'lurves-agent' campaign that deliver a small info-stealer and include prompt-injection, and a typosquatted claude-desktop.com site distributing a signed macOS DMG with malware; it also highlights PolinRider (DPRK) supply-chain activity and urges treating AI agents and signed installers with caution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.