Listen to a podcast, please open Podcast Republic app. Available on Google Play Store and Apple App Store.
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.
Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.
OpenSourceMalware provides community-driven threat intelligence on malicious open source assets including packages, domains, IP addresses, crypto wallets, and more.
https://opensourcemalware.com/
| Episode | Date |
|---|---|
|
Live from Strasbourg & Underground Economy
|
Sep 09, 2026 |
|
TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts
|
Aug 27, 2026 |
|
Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads
|
Aug 20, 2026 |
|
Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft
|
Aug 13, 2026 |
|
New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation
|
Aug 07, 2026 |
|
Hugging Face update, GitHub security improvements, DPRK linked to chald/debug, and more new PolinRider research
|
Jul 30, 2026 |
|
Hugging Face incident, AgentBaiting, RubyGems, CrashStealer, and new PolinRider research
|
Jul 24, 2026 |
|
Dependabot cooldowns, Jscrambler and AsynchAPI compromises, new PolinRider research
|
Jul 16, 2026 |
|
Open VSX security improvements, new PolinRider researcher, shady vendor practices
|
Jul 09, 2026 |
|
GitHub security improvements, shady vendor practices
|
Jul 02, 2026 |
|
How malicious OSS is evolving in 2026, feat. DPRK innovations
|
Jun 25, 2026 |
|
Mastra compromise, agentjacking research, busting malware myths
|
Jun 18, 2026 |
|
MSFT hit by Miasma worm, VS Code cooldowns, npm v12 breaking changes
|
Jun 11, 2026 |
|
Miasma npm worm hits Red Hat, new OpenSourceMalware research on 2026 trends, the Moika campaign
|
Jun 04, 2026 |
|
OSV false positives, Crowdstrike takedown of Glassworm infra, and MSFT nukes a researcher
|
May 28, 2026 |
|
GitHub popped by malicious VS code extension, npm staged publishing debuts
|
May 21, 2026 |
|
RubyGems bot attack, ShinyHunters ransom Canvas, and the latest on Mini Shai Hulud
|
May 14, 2026 |
|
Git hook persistence, Antrea compromise, Dirty Frag, cPanel exploitation, interpreted language malware
|
May 07, 2026 |
|
Lovable and Vercel incidents, GitHub RCE, EDR vs. AI agents, Mini Shai Halud by Team PCP
|
Apr 30, 2026 |
|
Bitwarden CLI compromise, npm lifecycle scripts, OWASP cheat sheet, cross-ecosystem attacks
|
Apr 27, 2026 |