The OpenSourceMalware Show #13
ID: fa4b6b83-b218-5be8-8e24-ef32bdd99e68
STIX ID: report--fa4b6b83-b218-5be8-8e24-ef32bdd99e68
Feed Name: OpenSourceMalware Blog
Date Published: 2026-07-16
Date Updated: 2026-08-06
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
**Executive summary:** This episode reports active supply-chain and repo compromise activity: JScrambler had malicious npm releases pushed via a stolen/published credential, AsyncAPI was abused through a disclosed GitHub Actions pull_request_target vulnerability to publish packages with Miasma-derived payloads, and new PolinRider (North Korean) research identifies ~2,417 newly poisoned repositories (over ~4,400 total) using config file injections, fake font/dictionary files and VS Code/task hooks to trigger malware; the hosts also note GitHub enabling a 3-day Dependabot cooldown by default and provide detection/hardening guidance for developers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
