# The OpenSourceMalware Show #17

> Source: <https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode17>
> Published: 2026-08-13 23:42:27.734289+00:00

BLOG

# The OpenSourceMalware Show #17

Live from Hacker Summer Camp! Keyv and cacheable npm worm, WEL1DROPPER AI slopsquatting campaign, NullReceiver DPRK C2 technique.

By cb482791-4ef1-4762-96ad-b0ca4bdd538e ·

*The OpenSourceMalware Show is available on *[YouTube](https://www.youtube.com/@OpenSourceMalware)*, *[LinkedIn](https://www.linkedin.com/company/opensourcemalware/events/)*, and as a *[podcast](https://podcast.opensourcemalware.com/)*.*

**This week we talked about:**

**Hacker Summer Camp trends.** Jenn and Paul share observations from Black Hat, DEF CON, and BSides Las Vegas last week, including a maturing AI security conversation that has shifted to focus on where AI still falls short, particularly the last mile of precision and finesse that still requires a human to verify. They also discuss the emerging challenge of identifying malicious AI skills, where the natural language format makes static analysis much harder than it is for traditional package ecosystems. And they revisit the recurring gap between security teams who understand binary malware and incident response and those who understand the open source software supply chain.

**GitHub revokes npm bypass-2FA token privileges.** GitHub announced it is closing a gap that let npm granular access tokens configured to bypass two factor authentication perform sensitive account, org, and package management actions.

**DPRK’s NullReceiver technique keeps spreading.** Following up on last week’s episode, Paul shares that the number of packages using the NullReceiver technique has grown well past the 7 originally confirmed, and that DPRK’s use of crypto payments for infrastructure like VPN services could offer new tracking opportunities for defenders.

## Resources

[00:00:00] **Jenn Gile:** Oh. All right, we are live. Uh, it is Thursday, August 13th. We are back from Las Vegas in our respective, uh, I guess I wasn’t gonna say time zones or hemispheres, 'cause it’s still the same hemisphere and time zone for me, but you know, you’re back in yours.

[00:00:18] **Paul McCarty:** I’m, I’m upside down again. I’m in the upside down.

[00:00:20] **Paul McCarty:** Um-

[00:00:21] **Jenn Gile:** Good job …

[00:00:21] **Paul McCarty:** and, uh, by, by the way, that transition to live, that happened fast. I was, like, sitting here typing. I was like, “You were like, ‘We’re live.’” I’m like, “Whoa, hey. Good day, everybody. Good morning,” is the case might be. I’m not quite caffeinated yet, but I’ll get there

[00:00:33] **Jenn Gile:** I think I need a little extra. Um, okay, so we’re gonna talk about some takeaways from last week in Las Vegas.

[00:00:40] **Jenn Gile:** We’re going to talk about some new activity that you’re observing with, um, North Korea in particular, like kind of a follow on to the NullReceiver stuff we were talking about last week. And hot off the press, we’re gonna talk about GitHub, um, revoking npm bypass 2FA granular access tokens. So let’s start with Hacker Summer Camp.

[00:01:00] **Jenn Gile:** Um, takeaway number one… Well, first off, let’s rewind. Uh, maybe not everybody listening knows what Hacker Summer Camp is, but it’s the nickname for, uh, a week in Las Vegas in the middle of the summer, hence summer camp, where a lot of the cybersecurity industry goes for conferences. And it used to be, I think, just three conferences, and now, like, there’s no way you could go to all of them.

[00:01:22] **Jenn Gile:** Um, there’s BSides Las Vegas and Black Hat and Defcon. Those are the three big ones. There was an unprompted thing. There was an AI summit. There was-- The list goes on. There was a ton of stuff. We went to BSides, Black Hat and Defcon. They all have different flavors. Um, you know, you see different things, you talk to different people.

**AI’s last mile problem**

[00:01:43] **Jenn Gile:** I think that’s part of what makes the week a little bit interesting for us, is it’s, it’s an opportunity to see a lot of what’s going on. Um, let’s start with AI first. So here’s my observation. Uh, and I kind of think of things sometimes in terms of conferences, because you-- like when you go to a conference, you start to hear like what a lot of people are thinking at once.

[00:02:04] **Jenn Gile:** So like last year, twenty twenty-five at RSA, the AI industry for security was very new, and a lot of the, um, narrative was about, uh, this is gonna be terrible . Basically, like, we’re all, like, headed toward, uh, doom. We don’t know what’s gonna happen, but engineering is going bananas, and we have no idea. Like, that’s how I would describe the very f-like, early conferences when AI, you know, driven stuff first started coming out.

[00:02:36] **Jenn Gile:** And then starting like last fall when I was at LASCON and then into the spring, what I started seeing more of was how security teams can operationalize AI to, you know, do their jobs more efficiently to keep up. Like it was a lot more practical. Um, you know, we’re starting to see another, uh, evolution, you know, in terms of it being practical, but also finding the edges.

[00:03:05] **Jenn Gile:** So, you know, Paul, you mentioned as we were prepping an observation that, um, the last mile is the issue at this point. Uh, so say more about what you feel like is missing, 'cause obviously it’s not perfect.

[00:03:19] **Paul McCarty:** Yeah, I mean, I think that the, y- you know, w- I was… We were getting this vibe even before Hacker Summer Camp, but then just talking h- to everybody at Hacker Summer Camp, and just we’re, we’re all using AI, we’re all using it in lots of different ways.

[00:03:32] **Paul McCarty:** And by the way, Anthropic, if you’re listening, you’re letting us all down. So basically everybody in cyber right now is moving off of your tools. Uh, and Jen, I saw your post actually- You saw my post? I saw your post. Codex, um, GPT-5.6 Sol. Like listen, I am no friend of the OpenAI team and Sam Altman. I think they’re part of the, the pending apocalypse.

[00:03:55] **Paul McCarty:** But that said, um, GPT-5.6 Sol, like it’s crushing it. It’s fast, it’s good. Um, so a lot of us are moving… And this is, Anthropic is just like, just, it’s the worst own goal ever. So anyhow, sorry, aside there.

[00:04:10] **Jenn Gile:** Yeah. You know- Well, I j- … it’s frustrating, uh, while we’re in that tangent. You know, I moved to Claude, uh, whenever it was, when everybody else did, 'cause I was frustrated with what was there, because what was there, you know, with Gemini was going downhill, and Claude was really great for a while.

[00:04:24] **Jenn Gile:** And the post that Paul’s referencing is me hitting a security roadblock with Claude this morning when I tried to get it to read one of my blogs, and it was like, “Oh, you’re doing something scary.” And all I had to do was change my post. This is the second time this week where I changed my, not my post, my, um, my prompt to be like, “This isn’t dangerous and there’s no malware in here,” and then give it the exact same thing.

[00:04:49] **Jenn Gile:** And it’s like-

[00:04:50] **Paul McCarty:** Really?

[00:04:50] **Jenn Gile:** That-

[00:04:50] **Paul McCarty:** That works?

[00:04:51] **Jenn Gile:** Yeah, that’s all… That works. Um-

[00:04:53] **Paul McCarty:** Interesting.

[00:04:54] **Jenn Gile:** I mean, granted, there was nothing scary and there was no malware- Right … so it shouldn’t have flagged it in the first place, but the fact that that’s the only thing I have to do to get around their, uh, security block, I have questions.

[00:05:08] **Paul McCarty:** Yeah. For me, when, because when I’m, when I’m actually analyzing bad stuff, what happens is I get 70% in, 60% in, and then Anthropic loses it- its shizzle, right?

[00:05:18] **Jenn Gile:** Mm-hmm.

[00:05:18] **Paul McCarty:** And the problem there is that I’m not done, and then I have to do a model switch, which is relatively easy now inside of Claude, you basically just change model.

[00:05:28] **Paul McCarty:** You drop down to Opus 4.6 or 4.7, which tend to be the go-tos, right? Sonnet 5 is pretty good, but I’m, I’m starting to get blocks in Sonnet 5 too as well. But Opus 4.6 and 4.7 still are the go-tos. But the point is that you’re, you’re like, you’re in, and like if you can’t get past that block, you now have done all this work and you spent a bunch of tokens and you haven’t gotten the, the, the payoff.

[00:05:49] **Paul McCarty:** Um, and that’s very frustrating. So that’s where I’m moving to, um, Codex and eventually when I get time, you know, doing some of our own model stuff. But anyhow, um, all of that aside, everybody’s using AI and I think all of us are realizing, yes, it’s two things at the same time. There’s the quantum state of AI epiphany, which is it’s amazing, it’s changing my job.

[00:06:11] **Paul McCarty:** It’s, it’s, you know, it’s life-changing like the internet was and you know, all these other big technologies. But That last mile, you have to carry that last mile. And if you don’t, if you don’t, it’s so freaking obvious that what you’ve delivered is shipped directly out of the agent because it reads a certain way, and it lacks finesse.

[00:06:33] **Paul McCarty:** And most importantly, it lacks precision. You and I have seen that ourselves when we give these big data sets to Claude, you know, and create these big technical, um, you know, posts, and we have to go through it. It just doesn’t get a lot of that right, and so you have to have a human to go through each one of those things and make sure that everything it’s saying is actually precise.

[00:06:52] **Paul McCarty:** And this lack of precision, I know I’m going on here, but that’s where I think everybody in, in our industry is kind of seeing this same kind of problem, is that it do- it lacks that precision and make… It assumes things that it shouldn’t, so.

[00:07:05] **Jenn Gile:** Yeah, I will say- I’ll stop there … um, I was, I think, um, pleasantly surprised, and maybe this is not a great thing that the industry agrees with us right now.

[00:07:15] **Jenn Gile:** But pleasantly surprised that a lot of people in the industry kind of agreed that they’re seeing a lot of issues with false positive if they just throw AI at malware analysis. And, you know, I actually talked to somebody I know who works at OpenAI. I won’t say who it is, um, I don’t wanna get them in trouble.

[00:07:31] **Jenn Gile:** But they did mention that they, um, they actually tell people, users, not to use it for the security purposes. So it’s… I mean, these are just not designed for vulnerability remediation. They’re not designed for malware analysis. It just, uh, goes to show that that additional expertise that you bring when you set up the model, and you give it the context, and you apply, you know, the static engineering, uh, static analysis between the, the LLM stages is necessary and probably not going away anytime soon.

[00:08:06] **Paul McCarty:** Yeah, I mean, we have a bunch of our own techniques here at OSM that I won’t go into detail 'cause I don’t wanna give away the, the special sauce. But the reality is that, um, I think a lot of people right now are trying to be cheap on tokens 'cause tokens have gotten really expensive really quickly. And they’re still not, we’re still not paying for the tokens, right?

[00:08:20] **Paul McCarty:** So we’re still like, you know, it’s gonna get worse before it gets better. And so because people are dropping down to some of these cheaper, faster models, what’s happening is they’re getting cheaper, faster outcomes out of findings out of what they’re shipping, right? And I’m seeing that myself when I look at some of the cheaper OpenAI models, Mini and Terra, for example.

[00:08:42] **Paul McCarty:** Um, you, you see discrepancies, right? And so people are trying to save money because they’re doing a lot of analyses, and they’re dropping down, and they’re not using these other things that are wrapping kind of precision around it, like the static analysis and some of the other things that we do. So you’re right, man.

[00:08:55] **Paul McCarty:** False positives from, from malicious package detection is going up. Um, not for us, but which is good. It’s going up

**Malicious AI skills are hard to detect**

[00:09:02] **Jenn Gile:** Um, so a natural segue from there is to talk about another theme that we saw, uh, in particular toward the end of the week last week, was people, uh, talking about malicious AI skills and developing tools, uh, with the intent of being able to tell if a skill is malicious.

[00:09:21] **Jenn Gile:** And, um, so myself included, I had a talk at DEF CON. Um, I talked to a couple other people who gave talks on it, and, um, you know, the general consensus right now is it is hard to determine if a skill is malicious, and it’s also hard to tell if sketchy-looking behavior is in fact malicious or benign. Meaning lots of skills do things and have no malicious intent behind them.

[00:09:52] **Jenn Gile:** They’re the official skills from like big companies, and on paper they just look bad. So that’s a challenging space right now. But, um, found out about three separate, uh, early tools that are designed to like, you know, stick the GitHub repo or the file or whatever in the browser, and then it’ll, you know, in some way analyze them.

[00:10:14] **Jenn Gile:** Um, I think there’s a lot of, you know, work to be done in this space. There’s a lot of Uh, unknowns. I don’t know that we’re gonna see anything super mature right now, but it may be very much like things were a year ago, where there’s a lot of experimentation, and then in three months or six months, the products that come out to deal with this may look very different.

[00:10:42] **Paul McCarty:** Yeah, I mean, the… You and I have talked about this before on, on the podcast, but, you know, the natural language barrier here, not barrier, but the natural language, you know, environment that skills exist in are just really hard to find malicious stuff in. So I think that you have to-- And I’ve, I’ve tried taking our own internal analysis engine and kind of tweaking it for skills, and it works to some extent, but it needs a proper, like, built for purpose thing.

[00:11:06] **Paul McCarty:** Because the, the problem is that the, you know, the rigor around these skills in terms of, like, a specific release with, you know, a hash and, and a way to tell that that was the provenance from that person’s machine pushed that, you know, uh, thing, that skill, none of that exists. It’s all just the Wild West.

[00:11:29] **Paul McCarty:** We’ve gone backwards. Like, all the things that we learned that we need to do in NPM, PyPi, we’re doing none of that over in AI skills land, right? And so because we’re lacking that rigor, you know, we just have to fall back on more AI 'cause static analysis doesn’t work because it’s natural… Well, it doesn’t work as well because it’s natural language.

[00:11:45] **Paul McCarty:** It’s just… It’s a very complicated space, um, and I, and you know, you and I were talking about this before we were rolling that, you know, a lot of these best in breed kind of point solutions in these individual places are gonna be the way to go until somebody kinda starts to wrap these together in bigger platforms.

[00:12:00] **Paul McCarty:** I don’t know if that’s necessarily gonna be the ultimate play here because this just moves so quickly. I think these point solutions are gonna be the better way to go, which means you just have to, like, manage a quiver of these things. But-

[00:12:11] **Jenn Gile:** Well, and as we talk about the way things have changed over the last, let’s say, twelve to eighteen months, you know, when MCP servers came out, there was a lot of like, “Oh my gosh, these are super vulnerable.”

[00:12:22] **Jenn Gile:** We saw lots of conference talks about all the ways that you could- Right … you know, exploit somebody through an MCP server. And I don’t feel like I see the same level of aware- of awareness with skills. Um- I

[00:12:37] **Paul McCarty:** agree.

[00:12:38] **Jenn Gile:** And I, I… Yeah, I don’t know why. It’s interesting

[00:12:41] **Paul McCarty:** I, I think the other problem is that just skills can be imported from multiple places on your disk.

[00:12:46] **Paul McCarty:** Like, there’s not one-- Like, it can be in the local directory. Like, you know, Claude and Codex look in three or four different places alone for, you know, in, in succeeding order. There’s like a, there’s a hierarchy of where it looks for these th- And so it’s just really easy for malicious stuff to drop bad skills into places and get it to be executed.

[00:13:03] **Paul McCarty:** It’s basically like dependency confusion. Instead of calling Jen’s version of, you know, the OSM modify, uh, you know, skill, you’re gonna run the bad guys because they dropped it in somewhere that gets checked before yours does. So, uh, just, uh, everywhere you look, there’s all these complexities, right? It’s just a very hard space to…

[00:13:21] **Paul McCarty:** We just kind of have to come to the realization as a culture, and I don’t know if we’re gonna be able to, that things like skills, we just need to be a lot slower about adoption of these things, and we’re not. Like, we’re- Yeah … we’re rushing ever faster at using these things, which is a problem.

[00:13:36] **Jenn Gile:** I think that’s true.

**The AppSec and SecOps knowledge divide**

[00:13:38] **Jenn Gile:** Okay, last, uh, topic that we wanted to hit on specific to Hacker Summer Camp, and then we’ll dive into some of the news and research, is around, I guess I would just say this is a continuation of what we’ve been observing of the kind of divide that’s present between the people who understand malware, who are typically in more of a SecOps, InfoSec, IR side of a, a company, um, versus the people who understand the software supply chain, who are, you know, more in the development and AppSec side of the company.

[00:14:13] **Jenn Gile:** And, um, because of the silos that tend to happen with those teams, like, there really is, I’m-- I don’t know. You know, for anybody who’s listening, I’m physically, like, pulling them apart 'cause that’s really- what it, what it’s like. But yeah, we’re, we’re, I th- I would say we’re continuing to see, you know, people in application security, certainly they understand malware is bad.

[00:14:36] **Jenn Gile:** Don’t, don’t, don’t do the malware. Um, but don’t necessarily understand, um, indicators of compromise or typo squats or, you know, I could, the list goes on. And then the people on the more SecOps side, uh, are more used to the binary malware that, you know, gets detonated and, and is handled, you know, hashes. You know, we had the conversations with people about VirusTotal.

[00:15:02] **Jenn Gile:** Um, yeah, so there’s, there’s still very much like a, an knowledge divide there, I think.

[00:15:07] **Paul McCarty:** I actually talked to the team or some of the team that was at DEF CON. They actually were at DEF CON in the malware village. The company, which is called Hex-Rays, I think, that makes IDA. And I was like, “I didn’t even know the name of your company.”

[00:15:20] **Paul McCarty:** He’s like, “Yeah, we hear that a lot.” But just when you talk about malware, they’re just like, “What’s your, what’s your binary analysis,” you know, “kind of toolkit?” And then I’m like, “I rarely use it.” Like, I rarely open up Binary Ninja or some of these other tools. Um, I have more lately. Uh, something I forgot to mention to you is I’m actually seeing an increase in binary-based, you know, software supply chain malware.

[00:15:39] **Paul McCarty:** I think because of just the, um, you know, people are vibe coding up stuff, and so a lot of it is Go based. Um, uh, like I was looking at this crazy Windows, I haven’t even talked to Jen about this, you have this crazy Windows thing that pretends to be this agent called Kelki, and this guy, this bad guy just built all these things.

[00:15:56] **Paul McCarty:** His OPSEC is crap. So mate, I think you’re gonna, you’re gonna be in for a bad time. But anyhow, I’m j… I am seeing an increase in that, but overall, you know, it’s still a vanishing, vanishingly small amount. Yeah. I do have one other thing to say about Hacker Summer Camp, which is not, not on the list. I wanna call out my man.

[00:16:12] **Paul McCarty:** I’m wearing his shirt right now, the Sick DEF CON 34. Um, this is the Off By One, um, uh, DEF CON official- Ah, this is from the- … DEF CON official- … the 1Password

[00:16:21] **Jenn Gile:** crew. Yeah. That’s a nice

[00:16:23] **Paul McCarty:** shirt. No, uh-uh. N-no, no. Isn’t that- It’s Off By… No, uh-uh. No. Oh. This is the Off By One guy. I don’t even know his name. Like, I, I introduced myself, and he didn’t say his name.

[00:16:32] **Paul McCarty:** Didn’t wanna take a picture, which is fine, like, that’s kind of his thing, but he has this amazing website. He does those metal shirts, like, basically he takes, like, malware concepts and makes it all metal and then sells them. I have a couple of them, and I love them. My kids love them too as well. But, um, this is how I introduced the idea of death metal.

[00:16:48] **Paul McCarty:** How do you introduce the idea of death metal to your kids? Like, that’s a interesting conversation. Anyhow, big shout-out to him. Thanks, man, I really appreciate it. It’s very sick. I’m gonna wear it all day and, and, uh, it’s going into my high rotation, um-

[00:17:04] **Jenn Gile:** All right, that’s it, we promise.

**GitHub revokes npm bypass-2FA token privileges**

[00:17:05] **Jenn Gile:** Um, so right before we started, you sent me an X post that I think Yeah, had just gone up this morning from npm. So let’s start there with npm’s announcement. I’m pulling up the blog now, and I’ll drop it in our, uh, comments so people can take a look at it. But essentially, they announced, um, that they’re revoking these tokens that can be used to bypass 2FA.

[00:17:33] **Jenn Gile:** I mean, there’s very obvious reasons why they would have decided to do this. I don’t think they actually… Oh, no, they did explain why. Um- Yep. So the reasoning they gave is, you know, i- if you’ve got a 2FA bypass token and you’re an attacker, well, gosh, that’s a real easy way to take over someone’s account.

[00:17:50] **Jenn Gile:** Um, and there’s not really a need for 2FA bypass tokens. So yeah, I think this is a good thing. What do you think, Paul?

[00:17:59] **Paul McCarty:** Yeah, I think it’s a great thing. It’s actually, you know… And when I read this, I was like, “Oh, I, I’d forgotten that this gap exists.” Um, and I’m very aware of this gap. I just forgot it exists.

[00:18:08] **Paul McCarty:** But yeah, this is-- I’m glad they’ve closed this gap. Um, that seems like it’s obvious, um, and we’re celebrating it now in August of 2026. But I mean, come on guys, this is probably something you could have done ages ago. But anyhow, that aside, not trying to be the jerk. Um- It’s a great thing. I also want to point out though, like all the other recent NPM, this thing is 81 words.

[00:18:30] **Paul McCarty:** It’s like, it is super short. I just made that number up, by the way. I don’t know. It’s a, it’s a very small number of words.

[00:18:38] **Jenn Gile:** It might- it’s probably more than 81, but it’s not a lot of words.

[00:18:42] **Paul McCarty:** But the point is that it just lacks a lot of the technical details. Um, you know, you can, you can get to it if you understand the, the, the background like Jen and I do, but I just…

[00:18:51] **Paul McCarty:** Come on, NPM. Can you just put a little bit more effort into explaining? 'Cause I think they don’t, for some reason I, I feel like they don’t wanna go into too much detail about the problem. They just wanna say, “Hey, we- we’re fixing it,” you know? Call it good and we’re okay. There’s no problem to see here. Um, so I, I don’t know, maybe I’m speculating, but I just…

[00:19:11] **Paul McCarty:** Can you guys put a little bit more effort into these things? Like, and Jesus, can you please offer a light mode for these things too? They’re so damn dark. My old ass eyes are, can’t read these things.

[00:19:22] **Jenn Gile:** You crack me up. Um, well, yeah. Net, it’s a good change. Wish there was more detail, but in this case, uh, I would say I have fewer questions about this change than we have- Yeah

[00:19:32] **Jenn Gile:** on previous ones. It’s pretty straightforward. Okay. It’s pretty cut and dry. I don’t know if you noticed. Yeah, yeah, yeah.

**Audience Q&A on MCP and CLI risks**

[00:19:32] **Jenn Gile:** Uh, we have a comment, uh, that I’m gonna go ahead and pop up on the screen right now. So, uh, somebody on our LinkedIn stream asks, uh, "MCP/CLI abstract risks. Can you explain and elaborate, please?

[00:19:52] **Jenn Gile:** Many thanks." Hmm. You wanna tackle that, Paul?

[00:19:55] **Paul McCarty:** Uh, MC- MCP, CLI, abstract. I, I don’t know if this is coming out of the conversation that- I’m

[00:20:00] **Jenn Gile:** not sure exactly what we were talking about earlier where CLI would’ve come in, but, um, yeah. Go for it.

[00:20:07] **Paul McCarty:** I don’t know. I, I don’t know if this was driven by the conversation we had at the panel.

[00:20:11] **Paul McCarty:** I did a panel at Cloud Village, um, on, what was that? Friday at Defcon, and I don’t know if this is coming out of that, but one of the things we talked about in that panel was I just talked about my personal experience around some of the CLI tools and how they interact with MCP. Um, and you know, just the kind of types.

[00:20:33] **Paul McCarty:** I guess I was talking at a high level about the types of problems therein- And one of the things I talked about is, like, there’s this intrinsic… It’s kind of this, like, it’s like what Thomas Roccia was talking about, you know, the, the s- AI security and the security of AI. I’ve, I was focusing in, in, in the Cloud Village less on the intrinsic kind of problems inside of MCP, right, which are numerous, um, and more about, like, the supply chain, 'cause that was in, that was the intent of the, the, the talk at Cloud Village.

[00:21:05] **Jenn Gile:** So I’m

[00:21:05] **Paul McCarty:** gonna take a, a stab and say this person is not- Yeah … asking about that. I just took a look at their profile. They don’t look to work in, uh, cyber- Oh … and I don’t think they were attending the conference. So, uh, maybe just, like, a real basic primer might be useful of, um-

[00:21:21] **Paul McCarty:** Yeah. Well, um, I wouldn’t call myself an MCP expert.

[00:21:24] **Paul McCarty:** I think, I think there’s a couple issues with MCP. One is that many people rushed them into production very quickly, and then they’ve sat mostly unmaintained since then. So that’s the first problem, right? Don’t be installing- Well, and

[00:21:36] **Jenn Gile:** I, I guess I would say many of them were vibe coded to begin with, and I know this because I know a lot of the people who developed them.

[00:21:43] **Paul McCarty:** The one main one that I had to deal with, and I won’t say how, was absolutely vibe coded in a short period of time, and it was absolutely, it was horrendous. But

[00:21:53] **Jenn Gile:** I mean, I think one- So a lot of these have a lot of the common security challenges that we see with software applications, so it’s not necessarily that new categories of risk have been invented.

[00:22:05] **Jenn Gile:** It’s that they all got crammed into one little piece of code that were, you know, one little component asset. Uh, and so they can open you up to several different kinds of risk that, you know, previously wouldn’t necessarily have all come from one place. When it comes to malware- We don’t see a ton of malware related to MCP servers.

[00:22:36] **Jenn Gile:** What I, I would say the extent that I’ve seen tends to be more like, uh, something pretending to be an MCP server- Yeah … but really it’s kind of, you know, baiting you to download it so that you download malware. But I would say typically with MCP servers, assuming it functions and does the thing that it says it does, probably it’s software vulnerability risk is the majority of what you’re getting there as opposed to malware.

[00:23:05] **Jenn Gile:** That’s just what I’ve seen. Paul, I don’t know if you- No, I

[00:23:08] **Paul McCarty:** mean, I, I agree with a lot of that. What I have seen too as well, like, uh, for example, the ServiceNow, I think it was the ServiceNow MCP server, the official one, somebody copied it and it, and it worked. It still did its job. It s- it did what it said on the tin, but then they also added, um, you know, extra- Mm-hmm

[00:23:22] **Paul McCarty:** basically. So I think the issue with MCP is that I’m gonna use old-timey language to describe something new. 'Cause h- the problem with MCP is that, like, an MCP server is typically just an NPM package or a Python, you know, it’s just source code that you install that does something and it acts as m- as middleware.

[00:23:38] **Paul McCarty:** So this is the old-timey language I wanna use. It’s like it’s middleware. It sits between authentication and specific tool choices and a LLM, a non-deterministic by design LLM. And therein lies the challenge is that, uh, MCP servers often have problems with role-based access and being able to, to, to, you know, differentiate and use granular kinda access controls.

[00:24:03] **Paul McCarty:** They have problems with non-deterministically, you know, choosing tools, right? That… Or you c- that’s what you design them to do. So, I mean- It’s just a, it’s just a huge problem space. And, uh, Jen’s right, a lot of it comes down to the fact that there’s a lot of vulnerability risk there rather than malicious intent risk.

[00:24:20] **Paul McCarty:** But absolutely, if you go to NPM right now, I would just… I would posit, if it’s less than a month old, anything that has MCP in the name, there’s probably a 61% chance it’s malicious, straight up, right? I’m, I’m just gonna say so.

[00:24:33] **Jenn Gile:** I know that’s, uh, uh, pulling it out of the air, but I would say probably true. Um, okay, so moving on.

[00:24:39] **Paul McCarty:** All right, 60, 60.5.

**DPRK’s NullReceiver technique spreads, funded by crypto**

[00:24:41] **Jenn Gile:** Yeah. Uh, you’ve got a couple of notes here for us to cover on North Korea stepping up some attacks on the software space. Uh, so last week? Yeah, last week, we talked about NullReceiver on the podcast, which is a new way that North Korean threat actors are, um, hiding their traffic. The way that I kind of explain this is just like a software application needs infrastructure to deliver the software application, you know, to get traffic in and out and to serve whatever images and stuff, you know, malware needs infrastructure also.

[00:25:14] **Jenn Gile:** Um, but the threat actor wants to hide the infrastructure so that you don’t know where that traffic is going. You don’t know that it’s going somewhere nefarious. And so this NullReceiver, um, technique is quickly becoming a go-to way for, uh, North Korean, uh, malware to kind of hide the second stage of what it’s doing, and that’s really the game.

[00:25:41] **Jenn Gile:** You know, they want to hide their behavior. So you’ve been seeing more and more of it. You’ve tied it now to the PolinRider campaign. I know when we talked earlier this week, we had seven, uh, confirmed packages that were using it. What are you seeing today?

[00:25:58] **Paul McCarty:** Yeah, I mean, we definitely have a lot more than seven now.

[00:26:00] **Paul McCarty:** Um, Nextron and a couple other companies, um, and, and individuals have been submitting things to OSM, NullReceiver stuff. Um, so in addition to what we’re finding and what I’m finding, we now have other orgs, uh, introducing it, too, as well. So you’re right, there’s been this, like, overlap between the PolinRider style campaign where they’re basically pushing malicious code to compromised assets.

[00:26:23] **Paul McCarty:** Um, but they’re inside of that. So the, uh, NullReceiver is a technique like EtherHiding that, that you said it a second ago, that DPRK North Korea uses to obfuscate where the next stage is coming from, right? That’s what n- NullReceiver is. PolinRider is a style, is a threat actor and a style of campaign that is an evolution of contagious interviews.

[00:26:48] **Paul McCarty:** So they’re, they’re, it’s, they both are overlapping here because, one, they’re two different things. But, um, anyhow, we called it in last week’s episode, which is that we said NullReceiver, like, you know, was gonna quickly become supplant the other style. And sure enough, it has. Like, we’re seeing it everywhere now, so.

[00:27:04] **Paul McCarty:** And it makes a lot of sense because it’s simple, it’s lean, and you can put EtherHiding behind it, and that’s, uh, we’re, we’re seeing it in all kinds of different variations. We’re seeing it where it’s replacing EtherHiding. We’re seeing where it pulls an IP and then that immediately then goes back into an EtherHiding, um, stage, which means that sometimes we see six and seven stages now in some of these kill chains.

[00:27:24] **Paul McCarty:** Um, but one thing that I noticed that I wanted to call out is that one of the things that’s great about NullReceiver that’s different than EtherHiding is it allows DPRK to kind of reuse what the next stage is and make it a lot easier for them to do that. So the point of it is that it’s very portable, and they can highly iterate it quickly, and it’s very lean.

[00:27:44] **Paul McCarty:** However, for some reason I’m seeing that they’re not doing that. So they, they were doing that. They were using a bunch of different IPs originally, but now they’ve kind of, uh, uh, kind of stalled on this one IP. Now, here’s the thing is that this IP is hosted in the UK. It has an RDP server. Uh, you can, like, you can go to, go to Shodan and you can see it.

[00:28:01] **Paul McCarty:** I’m not gonna say the IP right on the air, but, um, uh, you know, we have it in OSM. But, um, if, if anybody from, you know, the UK government, maybe NCSC is listening to our podcast, um, you know, maybe you wanna take a look at that or reach out to us and we can point you in the right… Or, you know, consume our threat feed 'cause we’ve got lots of this.

[00:28:21] **Paul McCarty:** You know, all these new IPs will be there for you to, to, to find. So yeah, they’ve kind of stalled on this IP gen for some reason, which means that, you know, we can collect data. Um, I shouldn’t probably be saying that too loudly, but there we go.

[00:28:34] **Jenn Gile:** Well, so why don’t you, for the people who are listening who maybe are not, you know, experts, 'cause again, we’ve talked about how people who are on the more code side may not understand the other side.

[00:28:44] **Jenn Gile:** Um- What would you be asking the NCSC to do if you could wave a magic wand?

[00:28:52] **Paul McCarty:** Well, the IP is hosted in the UK, which means that, um, UK law, uh, and the rule of law governs, right? There’s jurisdiction, which means that UK government could, and I don’t know, I’m, I’m originally American, so I would use American language, but could be…

[00:29:08] **Paul McCarty:** And I don’t know, I know I live in the Commonwealth now, but I’m, I don’t know all the language. Um, you know, the, the UK government could gain access to, um, uh, you know, the, the underlying server from the host, which is a company I’ve never heard of before, but I guess they’re relatively big. They are called Evoxt, um, and it’s just a VPS hosting service, like all these, right, are.

[00:29:33] **Paul McCarty:** Oh, this brings up a secondary thing, Jen. Ah, this is… I meant to put this on the list last night, but then I didn’t. Um, I saw, um, uh, DPRK has lots and lots of money tied up in crypto, and so they like to buy things with crypto because then it saves them from having to do the complicated laundering of crypto.

[00:29:53] **Jenn Gile:** Yeah, you don’t

[00:29:54] **Paul McCarty:** have to exchange your money and launder

[00:29:55] **Jenn Gile:** it. Right?

[00:29:56] **Paul McCarty:** Yeah.

[00:29:56] **Jenn Gile:** It’s convenient. You don’t have to launder it and lose, like, more than 50%. By the way, when they launder, they typically lose more than 50% of the value, right? They don’t have to do that. They retain all that. Well, you know one of

[00:30:04] **Jenn Gile:** the way they launder it is by gambling, and so - Yeah.

[00:30:07] **Paul McCarty:** Yeah, that too …

[00:30:08] **Jenn Gile:** that’s gonna

[00:30:09] **Paul McCarty:** Yeah. But that’s complicated Anyway, where are

[00:30:11] **Jenn Gile:** we going with

[00:30:12] **Paul McCarty:** this? He- yeah, where am I going with this? Jen’s like, “Where’s he going?” That’s the reason that they, like for example, Astrill VPN. Astrill VPN accepts crypto as payment for the VPN. So DPRK likes to use third-party services that accept crypto.

[00:30:26] **Paul McCarty:** This is where I’m going with it. Mm.

[00:30:27] **Jenn Gile:** Mm-hmm.

[00:30:27] **Paul McCarty:** And so I’ve now started seeing these third-party services, and I won’t talk about them this week, but we’ll, we’ll put more formality around it and talk about it maybe next week. But I’m seeing these third parties start to offer m- middleware, where they basically will, will take a crypto payment for a company that doesn’t accept it.

[00:30:44] **Paul McCarty:** And so we’re now seeing that with some registrars and hosting services. So the reason I bring this up is that we need to be aware of this, because that means that DPRK now is gonna be able to spread their services across a larger number of SaaS providers, hosting, registrars, all this kind of stuff. You know, proxy, um, uh, providers, all that kind of stuff.

[00:31:04] **Paul McCarty:** Um, so yeah, I think that’s something- Yeah,

[00:31:06] **Jenn Gile:** the way that I might, uh, uh, sum that up is certainly whenever possible, they choose not to spend money. You know, they choose free services. People know that. But at some point, as we are entrepreneurs ourselves, we know you have to pay for infrastructure at some point.

[00:31:22] **Jenn Gile:** So this is, you know, if they can pay for it with crypto and more places are accepting crypto, this can kinda maybe help us see where they, um, are putting their infrastructure and where they’re, where they’re spreading out to.

[00:31:35] **Paul McCarty:** Yeah. More, more to come next week or, or soon. Um, we’ll, we’ll leave it at that.

[00:31:40] **Jenn Gile:** All right. Let’s call it here. Um- Let’s do it … it’s, it’s been an interesting episode. Stay in touch. Let us know what else you wanna learn about. Uh, don’t hesitate to ask questions. Take care.

[00:31:52] **Paul McCarty:** Thanks for listening. Cheers. Bye-bye.
