# The OpenSourceMalware Show #15

> Source: <https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode15>
> Published: 2026-07-30 23:13:35.659652+00:00

BLOG

# The OpenSourceMalware Show #15

Hugging Face update, GitHub ships more security improvements, DPRK linked to chalk/debug attack, new PolinRider research

By cb482791-4ef1-4762-96ad-b0ca4bdd538e ·

*The OpenSourceMalware Show is available on *[YouTube](https://www.youtube.com/@OpenSourceMalware)*, *[LinkedIn](https://www.linkedin.com/company/opensourcemalware/events/)*, and as a *[podcast](https://podcast.opensourcemalware.com/)*.*

**This week we talked about:**

**Update from Hugging Face:** Hugging Face published a technical timeline of the OpenAI evaluation agent that breached its production infrastructure between July 9 and July 13, reconstructing over 17,000 attacker actions across the five day window. OpenAI's own follow-up disclosure this week revealed the agent didn't stop at Hugging Face. It accessed accounts on four other services during the intrusion. We dig into why the agent went after the ExploitGym answer key instead of solving the benchmark honestly, and what that says about reward-seeking behavior in autonomous agents.**GitHub ships publish-time npm malware scanning and holds risky GitHub Actions workflows:** On July 28, GitHub announced two supply chain security changes on the same day. npm packages are now scanned before they become available for install rather than after, and GitHub Actions will hold workflow runs identified as potentially malicious until a repository collaborator with write access approves them. Both announcements are thin on technical detail, and we talk through what triggers are probably getting flagged and why GitHub and npm have been slow to take on this kind of liability.**Amazon ties DPRK to the chalk and debug compromise:** Amazon published research attributing the September 2025 compromise of the debug and chalk npm packages, along with the typo-crypto package first seen in March 2025, to the DPRK threat actor tracked as SAPPHIRE SLEET. We talk about why this link wasn't news to researchers who've been tracking DPRK's tradecraft for a while, and why TeamPCP's loud, public style keeps pulling attention away from the North Korean groups doing far more financial damage.**PolinRider automation causes account takeovers without targeting:** New OSM research examined 20 npm and Go packages compromised through PolinRider's automatic credential harvesting rather than a deliberate account takeover. We explain why maintainers infected through fake job interviews and poisoned VS Code tasks ended up publishing malware to packages nobody had specifically targeted, and why that distinction changes how defenders should think about the threat.

## Resources

(report)

[Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident](https://huggingface.co/blog/agent-intrusion-technical-timeline)(blog)

[OpenAI Says Its Rogue AI Agent Didn't Just Hack Hugging Face](https://gizmodo.com/openai-says-its-rogue-ai-agent-didnt-just-hack-hugging-face-2000792374)(changelog)

[npm publish-time malware scanning and dual-use metadata](https://github.blog/changelog/2026-07-28-npm-publish-time-malware-scanning-and-dual-use-metadata/)(changelog)

[GitHub Actions holds potentially malicious workflows for approval](https://github.blog/changelog/2026-07-28-github-actions-holds-potentially-malicious-workflows-for-approval/)(report)

[Amazon identifies North Korean hacker group behind open-source supply chain attacks](https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/)(blog)

[Amazon Links Debug and Chalk npm Hijack to North Korea's Sapphire Sleet](https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html)(webpage)

[typo-crypto](https://www.npmjs.com/package/typo-crypto)

[00:00:00] **Jenn Gile:** It's Thursday. Thursday, July 30th, um, and we are back. We've got lots of things on the schedule to talk about. Some of these are follow-ups from things from last week. Some are, uh, pieces of somewhat breaking news. We've got a little maybe industry drama in here, and also some new research

[00:00:30] **Paul McCarty:** Uh, it's always funny, like when I work right up until the moment that we hit record, um, instead of like spending, you know, the usual hour that I do, well, when I can, researching things, it's always a little bit more YOLO. But that's okay. Um, I'm prepared. Well, I'm, I'm YOLO prepared

[00:00:48] **Jenn Gile:** Y- as, as prepared as we can be. Um, next week we are in Las Vegas. Um, it's surreal. It's only a couple days away. I was getting, you know, some of my pre-packing done earlier this week, but, uh, I think it's very possible we'll skip next week's recording, but we're getting together with a whole group of security research pals.

[00:01:14] **Jenn Gile:** We're gonna be doing a recording with our friend Mackenzie from over at Aikido. So, uh, it's, it's possible we might not make time to do our normal livestream 'cause it's gonna be chaos, but there'll be good stuff out there.

[00:01:29] **Paul McCarty:** You know, I, I, I know this is off script. I would love for us to do something. Um, I

[00:01:35] **Jenn Gile:** Oh, don't get me wrong, I'd like to do it. I'm just realistic that it's gonna be pure chaos

[00:01:40] **Paul McCarty:** It's true. It's very true.

[00:01:42] **Jenn Gile:** So we'll see. Might be a game time decision

[00:01:45] **Paul McCarty:** Fair enough. Fair enough. Let's do

## Update from Hugging Face

[00:01:48] **Jenn Gile:** let's start with an update from Hugging Face. Paul, did you get a chance to take a look at the, uh, after action debrief that they published, I think yesterday?

[00:02:00] **Paul McCarty:** Only very, very briefly. I glossed over it. I'm, um, taking a look at it again here. Um, I did notice that they mentioned that there's a, there was a second-- Uh, Hugging Face didn't mention this, but OpenAI had mentioned there was a second, um, uh, thing that got popped, company/project that got, that compromised.

[00:02:18] **Jenn Gile:** Uh, I read it was four.

[00:02:21] **Paul McCarty:** Oh, really? That's new to me. That's news to

[00:02:23] **Jenn Gile:** saw something-- I'm subscribed to the Axios newsletter, I wanna say, and, uh, I didn't get a chance to digest it all, but I think it's, it's more than two. So this model that they were, uh, training or testing rather, um, really went off the rails.

[00:02:41] **Paul McCarty:** Yeah. You know, and to, to that point, like if it really is, let's just say four, let's just pick that number. If it really is four companies/projects that got compromised, um, you know, that starts to make this, this starts to tip this, at least for me, back into the, you know, probably happened category 'cause, um, until there was, until there were additional, um, companies that had been compromised, uh, you know, I was pretty skeptical.

[00:03:11] **Paul McCarty:** You know, I think I made that clear last week and I'm, you know, I'm s- there's still part of me that's very skeptical, but, you know, with more evidence comes less skepticism.

[00:03:19] **Jenn Gile:** I'm gonna drop the link. It was, uh, StrictlyVC that I got this from. So let's see here. Here's a Gizmodo article about the OpenAI part. Uh, it was four different, uh, victims, we'll say. Uh, so full disclosure, I haven't had time to read it yet. I did look through the Hugging Face incident report. I think it's really nicely done.

[00:03:41] **Jenn Gile:** Um, this looks like it was a tremendous amount of work on their part. Um, they said that there were over 17,000 agent attacker actions that they had to analyze. Um, it happened over the course of... Let's see here. Where's the timeline? Uh, five days, I believe, and they caught it partway through.

[00:04:05] **Paul McCarty:** Yeah, July, July 9 to July 13

[00:04:08] **Jenn Gile:** Yeah. Uh, so this is, again, really nice debrief, um, or I guess analysis.

[00:04:15] **Jenn Gile:** They've got this really neat little, um, timeline thing at the top of the blog that you can play with that shows you, uh, everything that happened along the, the five-day, um, attack timeline. And then they've gone in and kind of talked about the changes that they made. Uh, no surprise, the model was able to take care- uh, take advantage of security vulnerabilities in their configurations that were not novel things.

[00:04:51] **Jenn Gile:** You know, they had, uh, something that was over-permissioned. They had credentials where they shouldn't have been. Um, you know, they acknowledge in the report like, "Look, this, these were basically, this happened because of security hygiene issues. We fixed them." Um, and I think I'd, I'd give them a lot of credit for making that comment.

[00:05:11] **Jenn Gile:** Um- What they said is that, and I think this is from OpenAI as well, that this model that broke in, the reason that it decided to head on over to Hugging Face is it was testing this benchmark, and it went to go try to steal the answer key from Hugging Face. And there's a couple of questions with that that I think are interesting questions to discuss.

[00:05:40] **Jenn Gile:** So one, um, why did it go seek out the answer key instead of just trying to solve the challenges that were put in front of it? And there's a couple hypotheses that are out there that I think are believable. Um, one is that some of those challenges, in fact, are not solvable, and the model in some way may have known this and said, "Well, I'm just gonna go circumvent 'cause I'm trying to get the highest score here."

[00:06:12] **Jenn Gile:** Um, some of the other hypotheses are around, you know, rather than attempting to, you know, do the challenges, that it wanted to get the best score that it could. And so instead of perhaps trialing-- trying and failing, it just wanted to go get the answers. It's all kind of coming back around to the task that was put to the model was, "Test this benchmark, get the best score you can." It heard the, "Get the best score you can," and said, "Oh, well, the best score will be on the answer key, so if I go steal the answer key, I can get the best score." And I think this ties back to something you and I have talked about, Paul, which is a challenge with really all models, is they're designed to do what the user asked for. And often that, um, core, like, do what the user asked for gets it away from what the user actually wanted it to do. In this case, OpenAI surely didn't need the answers stolen. It probably could've-- may, may have even had access to those somewhere else. You know, it wanted to actually test the model. Um, but the other being it broke numerous security policies in order to do it, you know, managing to jailbreak itself out of the sandbox, getting into Hugging Face, doing things that I don't know that anyone's used the word illegal, but, you know, certainly unethical, illegal behavior.

[00:07:49] **Paul McCarty:** Oh, I, I have. I've definitely heard multiple people on Twitter and LinkedIn, you know, basically ask like if a human did... In fact, I commented on one of them, um

[00:07:58] **Jenn Gile:** Yeah. If a human did this, what would happen? You would

[00:08:01] **Paul McCarty:** And that's what, that's what the person posited, right? And so my response was, uh, "What if I just tell the agent what to do and then I walk away?

[00:08:08] **Paul McCarty:** I'm good, right?"

[00:08:11] **Jenn Gile:** Yeah. So, um, feeling very much like I'm living in a late '90s, early 2000s apocalyptic AI movie right now.

[00:08:23] **Paul McCarty:** Right? Like we know, we know how this ends, Jen. We've all read the books. We've

[00:08:29] **Jenn Gile:** Literally we've seen the movie.

[00:08:30] **Paul McCarty:** we've seen the fricking movies. Like we know how this ends. Why are we just foolishly as a culture just running towards our inevitable end? Like, you know, the, the

[00:08:41] **Jenn Gile:** I will say, you know, I live in a community that's not a strong tech community. I had lunch with a couple of friends last week. One is a hairdresser, the other, uh, is an accountant. Neither are what you would call AI experts, and they both vocalized, "Hey, we're trusting this less and less. We're seeing the edges.

[00:09:02] **Jenn Gile:** We're understanding where it works and where it doesn't." And that conversation in itself honestly makes me feel better about where we're going of, I don't think people are quite as blinded by the technology as they may have been one to six months ago.

[00:09:22] **Paul McCarty:** Yeah. And I'm hearing kind of anecdotally the same kind of thing, both in my own network, you know, of humans and, you know, online in the places where I, I like to hang out. I-- You know, getting back to the Hugging Face thing in particular, got a couple questions that I need to research where this, um, where they say the third party launchpad was...

[00:09:43] **Paul McCarty:** I, I don't know if they s- it doesn't look like they're specifying what

[00:09:46] **Jenn Gile:** I don't think they named it, no

[00:09:48] **Paul McCarty:** Hmm, interesting. So yeah, stage one from OpenAI evaluation sandbox to a rooted launchpad. They talk about the first couple parts of those, um, and then yeah, the, the part that's in orange, the rooted, uh, Code avail sandbox, um, they don't describe that.

[00:10:06] **Paul McCarty:** And, and we have heard that, um, uh, JFrog's Artifactory was involved. Um, in fact, I think that Artifactory now is one of those four companies that was, um... You know, if I get this wrong, if I get this wrong, then next week I will, I will mea culpa on this, but my, my understanding based on some, um, signal conversations I'm having is that Artifactory is one of the companies that was popped.

[00:10:33] **Paul McCarty:** Um, but also that perhaps Artifactory itself was part of the escape. So if that's what they're referring to right there in that orange box, I don't know. Who knows? Um, but that aside, getting back to your point about, you know, the LLMs making you happy, they are, forgive the Philip K. Dick, um, reference here, but you know, they are LLMs and our agents are the pleasure bots of 2026.

[00:10:57] **Paul McCarty:** It is their job to make us happy, right? And yet, at the same time, there's this weird thing where once they get themselves going down a rabbit hole and they've kind of built up momentum, they just go off the rails. And so you have this weird quantum thing where they're trying to make you happy and give you what you want as quickly as possible, but they also have pivoted down a rabbit hole they didn't need to, and now they're just, it's like, um, what's that called when you s- you spend the time in it, so you're, you're, you're committed and you're, you just

[00:11:27] **Jenn Gile:** Oh, it's the, the sunk cost fallacy, I believe

[00:11:31] **Paul McCarty:** fallacy.

[00:11:31] **Paul McCarty:** Yes. Yes. Correct. Very good. That's exactly what I was thinking of. And that's what happens. I literally had this happen yesterday where I had Claude, very specific set of skills, some modulated determinism, which is where I have, like an LLM will interact with a stateful typed, you know, library and very narrowly focused, and then pop back out to an LLM stage and so on and so forth, hence the modulation.

[00:11:55] **Paul McCarty:** It was doing that, and then it just went off the rails, and I was like, I did not te- I stopped it, Control+C'd. I said, "I didn't tell you to do this. Why'd you do this?" And it's like, "Oh, you're right. I was, you know, I was trying to do this, but then I got too worked up in trying to figure this out." And I'm like, "Uh, yeah, I gave you explicit instructions and you just kind of, you know, pivoted."

[00:12:14] **Paul McCarty:** And, um, so I think both things can be true. Sorry, that was a bit of a rant there. But, um, you know, they are pattern matchers and they are, you know, trying to figure out what we want next, and so sometimes they just don't get it right

[00:12:27] **Jenn Gile:** Yeah, they get a little too excited. Okay, Paul, do you wanna talk about GitHub? Yeah. Do you wanna talk about GitHub now?

## npm malware scanning and GitHub Actions changes

[00:12:33] **Paul McCarty:** Oh. Oh man, I do. Which one? Do you wanna talk about the, the malware scanning thing?

[00:12:39] **Jenn Gile:** Yeah. Let me, let me summarize because two announcements came out. Uh, I saw them yesterday, but I think they actually came out on the 28th, um, July 28th, right? Pretty much at the same time. Uh, so in no particular order, the first announcement is that, um, they've made a change with GitHub Actions so that it will now, uh, hold potentially malicious workflows for approval.

[00:13:07] **Jenn Gile:** And then the other announcement, kinda two sides of the same coin, is npm is implementing publish time malware scanning. And these are both, um, very obviously meant to address, um, malware in the ecosystem. The GitHub Actions change is meant to prevent account takeovers, uh, in these circumstances, and I know you're gonna have a lot to say about this, where we've seen a GitHub Action exploited in order to, uh, push malware into a pipeline instead of having to steal a credential.

[00:13:46] **Jenn Gile:** And then on the other side, we have been crying for months, perhaps years, um, "Please npm, please take some responsibility and proactively scan packages." So I will say, uh, first of all, the intent here is good. Happy to see these issues being addressed. Um, as a follow-on, the information in their announcements is very thin.

[00:14:13] **Jenn Gile:** Um, the GitHub Actions workflow announcement is one, two, three, four paragraphs, but two of those paragraphs are, like, one line each. So very, very light on the, the information. Um, where do you wanna start, Paul?

[00:14:31] **Paul McCarty:** Well, let's start with the, the one that I have less immediate anchor about or, or, you know, passion about. Um, and by the way, did I just-- Sorry, uh, orchestration or sorry, administration stuff. Did I send you that blog post for the, my response to the, the GitHub act-

[00:14:49] **Jenn Gile:** feel like you were talking about it, but I don't remember seeing it. I looked for it while I was, um,

[00:14:57] **Paul McCarty:** Sorry, it got missed in that,

[00:14:58] **Jenn Gile:** But there, there will be a blog post from us ana- analyzing this, much like what you did on npm version 12. But

[00:15:03] **Paul McCarty:** Yeah. Yeah. And

[00:15:05] **Jenn Gile:** Yeah, go ahead

[00:15:06] **Paul McCarty:** and by the way, that blog post is one of the best things I've written. I really am pretty happy, pretty happy with it. Not to sound, that sounds terrible,

[00:15:13] **Jenn Gile:** That's a two-year-old horn, horn. Okay

[00:15:15] **Paul McCarty:** Uh, I'm very happy with it and I'm lo- looking forward to it, and I'll get that to you right away. But, um, yeah. Okay. So first let's start with the, the actions thing.

[00:15:24] **Paul McCarty:** I, I think y- there's like, there's no details in this. Like, this thing, like you said, I mean, this thing is tiny. This, you know, um, uh, when, quote, "When a workflow run is identified as potentially malicious and held, the workflow won't execute until repository collaborator with write access reviews and approves it."

[00:15:45] **Paul McCarty:** So that's gonna just, first and foremost, that's just gonna break a crap ton of GitHub actions. And maybe it should. I'm not arguing that's necessarily a bad thing. I would suspect, because there's no details here, there's like... I, this is, it's crazy how GitHub's, you know, PR is getting worse and worse and worse.

[00:16:03] **Paul McCarty:** Um, it makes sense though, because they keep losing people, so. Um, anyhow, uh, I would suspect that what they're gonna looking for is they're looking for specifically those, like, high-risk triggers that we all kind of know, like the, the Pwn request triggers, right? And this is like, this is like Francois and Ronnie and all those guys.

[00:16:22] **Paul McCarty:** This is their specialty. Adnan and all those guys, that's their specialty. But, you know, things like the pull request target trigger and workflow run, these are all things that run in the context of the originating, um, repository, and that's where the problems come up. So I'm gonna guess that if the execution engine sees some of those triggers in the workflow file, then it might just hold them, um, uh, or, you know, might look for, you know, might parse it for, to see what's happening there or what's being passed to it or something like that.

[00:16:56] **Paul McCarty:** But it might just be something as simple as like, you know, we're just gonna, we're gonna block on these triggers. Who knows? There's no details, so I'm just speculating.

[00:17:04] **Jenn Gile:** Yeah, I mean, as we're speculating, what would make sense would be to block some of these things that have been exploits in the last, what, six, eight months. We've seen GitHub actions abused several times. It's often, like you said, these Pwn request scenarios. So stands to reason that would be on the list of things to block

[00:17:27] **Paul McCarty:** Uh, I mean, I, I, I still wonder, and I wonder this with lots of things with GitHub and npm, but I still wonder why things like, you know, those, um, you know, those triggers still exist full stop. Like, why does, why does pull request target still exist? And the only reason why, let's just be very explicit, is because lots and lots of people still have it.

[00:17:49] **Paul McCarty:** I know, because you can just go and search GitHub and look for them. Lots and lots of people are still using it because they're too stupid and too slow to change it, to update it, right? And so because of that, GitHub doesn't want to create this massive breaking change. But they might actually be creating a, a breaking change here, maybe not quite as massive, in the form of these, you know, these stops, so these block actions.

[00:18:08] **Paul McCarty:** But we'll see. And here's the other thing, and this is going to blend into this next one I'm going to talk about. The reason that GitHub and npm have not wanted to wade into this space is because they don't want liability. What they don't want is they don't want to not block a GitHub Action workflow and then have it be malicious, and then the customer say, "I thought you were blocking these."

[00:18:30] **Paul McCarty:** And GitHub will be like, "Well, we are, but it didn't look like it was malicious." And then the customer's like, "Well, that's because your, your detection is bad," or s- you know, whatever. Like, this is the presumed back and forth. You know, and there's, unfortunately, there's, you know, legally there's like, um, that, that is important, you know, crossing that, breaking that plank is important.

[00:18:51] **Paul McCarty:** So, all right. Now, let's talk about the scanning malicious packages. In April, uh, April 1st, April Fool's Day, I shizz you not, that was really hard. I shizzle you not that April Fool's Day, GitHub came out with an announcement saying, "Hey, we are now scanning all npm packages." Zach came out with it. It was legit.

[00:19:15] **Paul McCarty:** It was not a April Fool's joke, it was legit. Um, why they decided to do that on April Fools, who knows? But, um, you know, like I said about GitHub PR right now. So, they have been scanning packages since at least April, and the reality is they've been doing it before that. So they, you know, the inside baseball is that Microsoft built some scanning technology, and they've been using that for months and months and months.

[00:19:36] **Paul McCarty:** Actually, over a year, I think. Um, but then Zach mentioned that, you know, in April that they're doing it now on all packages. Now, the difference, the difference between what happened on April Fool's Day and two days ago is that the difference is now they're moving the scanning to before something is published, and this is a big deal.

[00:19:56] **Paul McCarty:** Um, the, the reality is that if they can stop these packages from ever entering the, the ecosystem, then it's just less opportunity for these things to get pulled into artifactories and, you know, the Nexuses of the world and the Verdacios of the world and all those other places where we store packages.

[00:20:14] **Paul McCarty:** Um, that having been said, it is so poorly described and so lacking in technical details that it's like It's stunning in its lack of details. I just, I just, I'm

[00:20:31] **Jenn Gile:** that's the best way to put it. I read it and it's got more detail than the GitHub Actions one, but that's a low bar. Um, what we

[00:20:41] **Paul McCarty:** It's like I, I killed less people than last time

[00:20:43] **Jenn Gile:** Oh, goodness. Um, so they said that it's typically gonna take around five minutes for a scan. Uh, at peak times or if the package is big or complicated, they say it can take 15 minutes or more.

[00:20:58] **Jenn Gile:** Um, they're not saying a lot about what kind of behavior they're going to be looking for, which is a similar comment that you made about GitHub Actions. Um, I think it's, it's always a challenge to, you know, be blunt. How much do you share publicly so that threat actors, um, don't understand what you're looking for versus so that your users realize what the, the security policies are?

[00:21:31] **Jenn Gile:** Um, it's probably, in their opinion, safer to be vague about it, and then if you're an enterprise customer you can probably get more information about how this is going to work. But they're saying that if a package is blocked, the publisher may receive a notification with the option to appeal. I think the choice of the word may is, uh, it's a choice, so, uh, I interpret that to mean you might also not receive a notification.

[00:22:01] **Jenn Gile:** Um, one would think that that would happen in cases where they think the publisher themself is malicious and then they don't tell them and they probably just kill the account. Um, but yeah, not a whole lot of detail and then they link to the acceptable use policies.

[00:22:19] **Paul McCarty:** Oh, I wanna make a correction. I'm pretty sure GitHub came out with that statement about scanning all packages April 1 of 2025. I will verify. I was looking for it in the background right now. But if that's the case, their scanning has been in place before Shai Hulud and Axios and Chalk and Debug and all of the shizzle show that we've been dealing with in the last year.

[00:22:45] **Paul McCarty:** Even if it is April of this year, there still have been a bunch of high-profile software supply chain attacks involving npm packages that have happened. So, and I'm pretty sure it's last year, so,

[00:22:56] **Jenn Gile:** Yeah. I mean, regardless of when it was implemented, um,

[00:23:01] **Paul McCarty:** Not

[00:23:01] **Jenn Gile:** you and I were talking about earlier today, there is a lot of malware in npm right now that people know is there that has public reports on it. Um, we're gonna talk about one of those actually next. Uh, I'm sure you have more to say about the malware scanning,

[00:23:18] **Paul McCarty:** I, I do. What we'll do is we'll c- we'll, we'll punt that until next time, whether that's next week or the week after that, when after my blog post comes out, because then I can reference specific things. I don't wanna hit every bullet point from the blog post now. So yeah, let's talk about this. I love this.

## Amazon links DPRK to the chalk / debug attacks

[00:23:33] **Jenn Gile:** Okay. Uh, next on the list is a blog that came out from Amazon today, yesterday? What's the date on this? Yesterday. Uh, the title of the blog is Amazon Identifies North Korean Hacker Group Behind Open Source Supply Chain Attacks. I promised a little, um, drama here. I think, Paul, I'll let you take the lead.

[00:24:00] **Paul McCarty:** Oh, I wanna choose my words very, very carefully here, 'cause, um... Um, okay.

[00:24:06] **Jenn Gile:** have friends all over and we're not here to throw rocks. I'm just gonna start with that

[00:24:10] **Paul McCarty:** I've got friends in all these companies and, um, I wanna navigate this in a way that's respectful to their work and at the same time is honest about some of the failings in publications, research, whatever. So I think the first thing is that Amazon's main point in the, the recent, um, uh,

[00:24:33] **Jenn Gile:** Article, yeah

[00:24:34] **Paul McCarty:** article, thank you, jeez, um, uh, you know, that came out yesterday is that they have tied the chalk and the debug, uh, packages, uh, account takeover attacks from last year to DPRK, and they make it sound like they're the first ones to do this.

[00:24:53] **Paul McCarty:** And the reality is that Charlie at Aikido has been saying this publicly for a while. We've been all saying this. I think I've said it several times, you know, in, in talks and whatnot. Um, it certainly was a known thing. It wasn't like we were hiding it. We didn't have specific attribution, but the reality is that, like, when you're in the guts of DPRK malware as much as I do, like, th- th- you know, like it just looked and smelled like, you know, a lot of the other stuff.

[00:25:17] **Paul McCarty:** I mean, it was unique and not saying that it was exactly the same, but, you know, it definitely looked and felt like DPRK and, you know, sure enough, the closer you got to, the more it looked that way as well. So, um, so I guess the first thing is like, you know, Amazon taking credit for saying that this is DPRK and being the first ones to say it, which is what they explicitly say in the report.

[00:25:37] **Paul McCarty:** Oh, it was a bit of a stretch. So then Hacker News, Jack the-- Hacker News comes out with a, a, a blog post yesterday on Hacker News, or earlier today actually, basically just like questioning much of the

[00:25:53] **Jenn Gile:** Everything in the blog, yeah. It's, uh, it's got an interesting tone to it

[00:25:58] **Paul McCarty:** It has. Now, what is interesting is that there are a couple of-- Amazon does have some good detail in, in the, um, uh, the report, and I not- noticed some chatter from the Seal team, uh, people, um, uh, you know, talking about it as well.

[00:26:18] **Paul McCarty:** And there was, you know, the I- so basically in the report was an IP address and a, and a domain name, AWS something store or something like that. No, no, sorry, npmjs.store, um, and a IP address. Now those IP add- the IP address in that domain were already out there known. The Seal team pointed that out. You know, we had some of that data inside of, of OSM as well. Um, but it is, you know, it, it's good and to tie it to that, and they also talk about this package typo. Was it typo core?

[00:26:51] **Jenn Gile:** Typo dash crypto

[00:26:53] **Paul McCarty:** Yeah. Now here's the thing, people, and, and Amazon does refer to this like as a compromised package. It's not. It's, it's net malicious by DPRK.

[00:27:04] **Jenn Gile:** Yeah, it's a typo squad

[00:27:05] **Paul McCarty:** it's a typo squat, right? Just, it's just a, it's like one of the hundreds that DPRK publishes every day, right? Like, it's, it's not unusual. Here's the thing, though, is it's still, still on NPM after over a year.

[00:27:18] **Paul McCarty:** Um, so if you wanna do some research and you wanna grab a payload, and it's still, unfortunately, I just tested right befo- I literally right before this I was testing it. It's still live. Now, here's the thing, is that because they pull, because they've been using the, the, um, the ether hiding technique for months now, um, the payload that you get today is not the payload you would've gotten, you know, in the middle of 2025.

[00:27:40] **Paul McCarty:** So let's just be very clear, like the, the IoCs that we've extracted today are not necessarily the IoCs that we have. But, you know, I can't go backwards in time and, and figure that out, so that's, you know, that is what that is. But, um, yeah, it's just all really interesting just watching it with the popcorn.

[00:27:54] **Paul McCarty:** Um, and I think it's, you know, it's a bigger example of what's happening right now in the security ecosystem, which is that everybody wants to stay, say how much they're doing. Everybody is announcing that they've discovered the same thing all at the same time, right? And it's f- kind of frustrating, especially for those of us that have been here for a while when nobody else was here doing this, um, to hear everybody saying, talking about how awesome they are and how they're discovering things that you've already discovered and had inside your platform for months.

[00:28:21] **Paul McCarty:** But anyhow

[00:28:23] **Jenn Gile:** Well, uh, kind of taking it back to the announcement itself, um, where I think there's some value here is there's been a lot of public attention on TeamPCP, uh, and they have been, you know, synonymous with account takeovers. Um, DPRK intentionally is not trying to catch as much attention with these attacks.

[00:28:50] **Jenn Gile:** Um, I'm gonna share a link to a podcast that, um, was referred to me. It just came out recently. The list To Catch a Thief is on North Korea. It's quite good. I was listening to the first episode last night. Um, but their, you know, MO is to make money and to fund their, uh, economy and their weapons development.

[00:29:13] **Jenn Gile:** And if you think about motivators, um, that's not what TeamPCP is doing. They don't have a country to run. They don't have missiles to develop. And, uh, being loud and splashy and bragging aligns with whatever it is their goals are. Um, whereas with North Korea's goals are much more, uh, economic and, you know, to some extent I'm sure they would like to get some intelligence, um, you know, in the US economy.

[00:29:44] **Jenn Gile:** And so if that's your goal, then you don't wanna be as obvious. You don't wanna be as easy to link. And I think the reason nobody has been loudly talking, you know, claiming linking Chalk and Debug to DPRK is, to your point, it smells like it. It looks like it. Can we prove it? Probably not. But do we have a really high certainty?

[00:30:09] **Jenn Gile:** Yes. The same thing with Axios, right?

[00:30:12] **Paul McCarty:** Yeah, I, and I mean, I think there were, you know, I th- I think there were some pretty hard signals. Like, I think that there was shared C2 infrastructure, and I think there were-- there, there was evidence. It's not like this was just con- complete conjecture. So, um, uh, you know, I, I, I

[00:30:29] **Jenn Gile:** No, I wasn't suggesting it's conjecture at all. It's, it's strong, yeah

[00:30:34] **Paul McCarty:** Yeah, sorry, I wasn't suggesting that you were suggesting. Um, I, I think that the... As a really good example of what you're talking there, Jen, about is I went to-- I've gone to two events in the last week and a half, and at both of those events I... 'Cause I have these really interactive talks. I like asking the, the audience questions.

[00:30:51] **Paul McCarty:** And I asked the audience, "Who's heard of Contagious Interview?" And in the first audience, I don't know, maybe eight to 10 hands went up. And then I asked who's heard of TeamPCP, and about three times as many hands went up, right? And I did the same thing at BSides Adelaide the other day. Contagious Interview got maybe five or six hands.

[00:31:07] **Paul McCarty:** TeamPCP got like 30 hands. So the reality is, to your point, we've been focusing on this squeaky wheel that really hasn't been, you know, causing the damage that DPRK has while we've been completely ignoring the professionals that have been over there making over $2 billion last year. And I think you and I both want us to kind of reset, you know, the talking points here.

[00:31:31] **Paul McCarty:** Let's focus on who's really, you know, especially now that TeamPCP's on the run. DPRK is not on the run, right? They're pretty safe. So, um, yeah, sorry. Talking points reset.

[00:31:42] **Jenn Gile:** Yeah, I think that's a useful framing. Um, many people in the community discount or, um Perhaps, and I shouldn't say the security research community, 'cause much of that community is well aware of what DPRK has been doing. But the tech community doesn't necessarily associate North Korea with sophisticated cyber crime, and that's a mistake.

## PolinRider research and automated account takeovers

[00:32:08] **Jenn Gile:** Um, and so as we're talking, uh, for the rest of this episode, the last topic that I have is some research I published today on DPRK activity. So a little backstory here. I was reading, uh, a blog from Socket earlier this week about the compromise of two packages in, um, an ecosystem called Joyfill, which is kinda like a PDF generator.

[00:32:34] **Jenn Gile:** And that's nothing new. You know, we see little compromises like this all the time. But what was new is this is a legitimate package. This is not, uh, you know, like that typo crypto package. This is not typosquat. And Socket found, uh, PolinRider signatures. And so while DPRK does do account takeovers, what we have not seen is account takeovers where, uh, the PolinRider infrastructure was involved.

[00:33:06] **Jenn Gile:** And so I went really deep, maybe too deep, I'm still in it, um, looking at, uh, uh, more of a, a bigger cohort of packages that we found that kind of have a similar shape. And so I looked at, uh, two packages that, um, JFrog found a month or two ago from a small developer, and then, uh, a collection of 16 Go modules.

[00:33:38] **Jenn Gile:** So these are all, you know, these three groups are all from different maintainers. None of them are very big. All of them had PolinRider signals. Uh, went ahead and confirmed, yes indeed, they are all PolinRider related. Um, but the reason that these are account takeovers is different than what we're used to.

[00:34:01] **Jenn Gile:** So if we start with like a definition of what's an account takeover, what we typically think about is there's a legitimate maintainer who is explicitly targeted by a threat actor because they have access to a project or projects that are high value. So Axios, great example. Chalk Debug, great example.

[00:34:23] **Jenn Gile:** These are maintainers that have just an enormous blast radius if you can get into their infrastructure. So they find a way to compromise, uh, the maintainer in a way that lets them publish a malicious version, and that's the, you know, genesis of a typical account, account takeover. That is not what happened with these 20 packages that I investigated These are ones where, um, the compromise is, uh, you might say that it's somewhat upstream from those packages.

[00:34:55] **Jenn Gile:** These maintainers at some point consumed the PolinRider set of malware, and PolinRider tends to target individual developers, which is a pattern I saw in these 20 packages with a couple exceptions. They're like single maintainer type situations, not affiliated with a company. And their MO is to get in quietly.

[00:35:19] **Jenn Gile:** Usually, the malware fires on a VS Code task JSON, which is exactly what happened in these cases. And then, uh, it looks for credentials, and then it continues kinda doing its thing with those credentials. But those maintainers are not necessarily targeted. Now, they may come in through the contagious interview campaign, in which case they were targeted by somebody, but not for like a big account takeover.

[00:35:45] **Jenn Gile:** They were targeted to get persistence on their machines, and these account takeovers are evidence of the automation that's possible with this PolinRider malware. And that's like ATO through automation. These are almost a, "Oops, we didn't really mean to do that, but cool, we're glad we managed to, you know, pop your project."

[00:36:06] **Jenn Gile:** Like, they did mean to do it, but it wasn't the targeted ATO strategy that we tend to see.

[00:36:14] **Paul McCarty:** Correct.

[00:36:15] **Jenn Gile:** there.

[00:36:17] **Paul McCarty:** Yeah, no, I mean, it's, it's all g- it's all great research. Um, I think that, that we generated a lot of data, um, and, you know, sifting through that data has been a challenge, so good work there, Jen. Um, I think the, the, the way that PolinRider is working, like, and I said this at, at least one of these conferences I was at last week, contagious interview, the kind of classic LinkedIn recruiter style.

[00:36:45] **Paul McCarty:** You know, I, I found one this week just on Twitter randomly and, and then posted about that. But that takes a lot of energy, right? You have to have a human in Pyongyang or somewhere else that's managing this stuff, creating this stuff, then interacting with humans. You know, sure they're using some automation along the way, but the reality is that you have to have humans, you know, DPRK operatives managing

[00:37:05] **Jenn Gile:** media s- or a, a social, uh, oh my gosh, words. Social engineering scam. You need

[00:37:11] **Paul McCarty:** Oh,

[00:37:11] **Jenn Gile:** to social engineer

[00:37:13] **Paul McCarty:** Yeah, it's in for it. And what PolinRider does is it basically just gets rid of that need for humans to be managing and orchestrating, and instead just creates automation. And you have to, watching some of these payloads pop in a sandbox where like within like less than a second, it's already, you know, dropping payloads into GitHub actions and stuff like that.

[00:37:34] **Paul McCarty:** It's pretty phenomenal. Um, you know, you gotta, you gotta give them credit. Um, and so I think people that don't, the InfoSec that doesn't really have visibility, and one of the reasons I like going and doing these kind of, you know, InfoSec heavy, you know, like financial services stuff and whatnot, is because InfoSec there hasn't really been, um, you know, kind of exposed to software supply chain attacks and don't realize that in a lot of cases, North Korea, they, they are creating more of this than everybody else combined.

[00:38:04] **Paul McCarty:** I don't know if that's actually true statistically, but it certainly feels like that, right?

[00:38:08] **Jenn Gile:** I believe it

[00:38:09] **Paul McCarty:** uh, yeah, I mean, I think it's true. I wouldn't have said it if I didn't think it was true. I just don't have the data right now to, to back it up. Um, I'll work on that for next

[00:38:18] **Jenn Gile:** Yeah. I mean, I guess the net here is we are going to see more. This is the continuation of a pattern where DPRK started by compromising GitHub repositories. Paul, your research that we published a week or two ago shows thousands and thousands of compromised, mostly individual developer repositories.

[00:38:44] **Jenn Gile:** That's kind of stage one. Stage two is it, the malware leaks into whatever those people own, and you and I debated, like, do we, do we go as far to call this a worm? It's not really a worm, but it's got some real worm-like behavior. Like, as I say in the blog, when is an ATO not an ATO? When is a worm not a worm?

[00:39:05] **Paul McCarty:** Right

[00:39:06] **Jenn Gile:** bit of that with this, um, this behavior. And, you know, as I was falling down the rabbit hole and, you know, prepping for our, our show today, I found yet another, a PHP package that, um, is part of this, we'll call it leaking of the malware out of Git repositories into packages, or as you called it, you know, jumping the fence.

[00:39:28] **Jenn Gile:** We're gonna see more of these compromised packages that come through this way and, you know, they're not, um, typically high-download packages. They tend to be pretty niche because it's individual developers getting popped. However, it's not gonna stay that way. We're gonna see someone somewhere bigger get hit with this

[00:39:52] **Paul McCarty:** Well, and we have seen PolinRider over the last six months. We have seen it penetrate into very, very large ecosystems. Um, so in particular, um, the, the developer, the single developer that manages Neovim got compromised. Um, and so, and, and it found-- PolinRider found itself into a VS Code extension. So, um, you're right, we're gonna see this.

[00:40:13] **Paul McCarty:** But I think the important thing is here is it doesn't have to... This, for this to be successful, PolinRider does not have to get into OpenSearch or LightLLM. It doesn't have to do that. It just has to get into all the little packages that all these develop- And they've, there's tens of thousands of people now that, that have this, right?

[00:40:28] **Paul McCarty:** So it doesn't have to be in these big ones. In fact, if it gets in the big ones, that's when they, we get a lot of visibility and people will start taking account. If it stays in these little tiny ones, you know, in these medium, you know, 100 stars or whatever, then, you know, nobody's really talking about it.

[00:40:43] **Paul McCarty:** And meanwhile, it's doing what it's supposed to be doing, which is self-replicating, which is the whole, that's the, the first

[00:40:49] **Jenn Gile:** Yeah

[00:40:49] **Paul McCarty:** Yeah. The firm we- worm Turing test. Are you, are you a worm or not? Is that, are, do you self-replicate, right? And the reality is that this is absolutely self-replicating. So you and I don't wanna use the word tur- worm because we just don't wanna get in this flame war with, with everybody else about it.

[00:41:05] **Paul McCarty:** But, um, the reality is, you know, like you said, it, what, it's a worm. We're just not calling it a worm

[00:41:11] **Jenn Gile:** Yeah. Well, it's interesting stuff. Uh, I was at an event last night where I got to talk about it. I'm looking forward to talking about it next week in DEF CON. We're gonna be talking about how to threat hunt in GitHub. We've got all kinds of stuff going. I think this is a good place to wrap it up.

[00:41:29] **Paul McCarty:** I agree. Thanks everybody for listening. We really appreciate it

[00:41:32] **Jenn Gile:** Have a great week. Uh, we may or may not be here next week, but we will be in Vegas for sure. Come say

[00:41:39] **Paul McCarty:** Also

[00:41:40] **Jenn Gile:** All right, take care

[00:41:41] **Paul McCarty:** See you guys
