# The OpenSourceMalware Show #21

> Source: <https://opensourcemalware.com/blog/opensourcemalwareshow-episode21>
> Published: 2026-09-16 23:55:35.461867+00:00

BLOG

# The OpenSourceMalware Show #21

Mini Shai-Hulud npm resurgence, OpenSourceMalware one-year anniversary, and Underground Economy conference Q&A on DPRK myths and GitHub security gaps

By cb482791-4ef1-4762-96ad-b0ca4bdd538e ·

*The OpenSourceMalware Show is available on* [YouTube](https://www.youtube.com/@OpenSourceMalware)*,* [LinkedIn](https://www.linkedin.com/company/opensourcemalware/events/)*, and as a* [podcast](https://podcast.opensourcemalware.com/)*.*

**This week we talked about:**

- **New research alleges OpenAI agents were behind the RubyGems attack.** A report from independent researchers argues an OpenAI agent swarm is responsible for the GemStuffer campaign, which uploaded hundreds of spammy packages to RubyGems in May. Truffle Security’s Luke Marshall followed up with the vulnerability the agents used (a CDN misconfiguration) that could expose other users’ RubyGems API keys. OpenAI has yet to comment on either report.
- **“lurves-agent” campaign typosquats PyPI packages to target AI users.** The campaign name comes from a string the malware’s own AI-generated code self-attributed inside a bash script, suggesting the threat actor used an AI agent to write it without reviewing the output. Across five or six packages typosquatting OpenAI and other AI framework names, the payload is a short info-stealer, and the surrounding comments function as a prompt injection aimed at any AI reviewing the code.
- **A typosquatted Claude site is distributing signed Mac malware.**[claude-desktop.com](http://claude-desktop.com) delivers a signed DMG instead of the real Claude desktop app, taking advantage of the fact that official install instructions for tools like Claude and OpenAI’s CLI have changed repeatedly over the past year, making people less careful about where they install from.

## Resources

- (report) [OpenAI agents carried out an undisclosed cyber-attack on RubyGems](https://www.rubyhack.ai/)
- (blog) [We discovered a Ruby account takeover; Rogue OpenAI Agents exploited it 2 months prior](https://trufflesecurity.com/blog/rogue-openai-agents-rubygems-takeover)
- (threat feed) [lurves-agent records on OpenSourceMalware](https://opensourcemalware.com/?tag=lurves-agent)
- (LinkedIn) [Three Injections and a Rootkit: How Lurves PyPI Typosquat Attacks…](https://www.linkedin.com/pulse/three-injections-rootkit-how-lurves-pypi-typosquat-attacks-chi-tran-eqm5c/)

[00:00:01] **Jenn Gile:** Hello. It is Wednesday, September 16th, and, uh, we have three topics on our agenda ta- to talk about. Uh, interestingly, none of them are about DPRK or PolinRider. Uh, so if you’ve gotten tired of us talking about those topics, good news, we’re not gonna talk about them today. I mean, no promises, but we’re not planning on it.

[00:00:25] **Jenn Gile:** How’s it going, Paul? I’m

[00:00:25] **Paul McCarty:** not pro- I’m not promi- I’m not promising anything. I, I wouldn’t make you There’s a lot going on in the space, so there you go.

## OpenAI agents suspected in RubyGems’ GemStuffer campaign

[00:00:33] **Jenn Gile:** So, uh, late last week I was heading back from Europe and, uh, in the Absolute AppSec community, somebody shared a, uh, a URL and said, “Curious what you think about this.”

[00:00:47] **Jenn Gile:** And I’ll, um, drop it in the chat, but essentially this is new research that has come out about the Gem Stuffer campaign in RubyGems. So let me see here. I can click, click, click. Here’s the research if you haven’t seen it. The TLDR is there was a big attack on RubyGems back in May. Uh, it was unattributed at the time.

[00:01:10] **Jenn Gile:** It was very spammy. Uh, these researchers are alleging that this campaign was done by rogue OpenAI agents. And, um, while we don’t, I guess, categorically know if that’s true, I think it also wouldn’t surprise us. So they cited, uh, three main reasons that they think an OpenAI agent swarm was responsible for the incident.

[00:01:36] **Jenn Gile:** First, they said the packages are clearly LLM authored. I’m not sure that I agree that that’s evidence that it was OpenAI agents, but sure. Um, the second is they’re saying the agents self-identified as being from OpenAI. Okay, that’s stronger evidence. Um, many of the packages uploaded contain an OAI in their name.

[00:01:58] **Jenn Gile:** Um, several have that as their author. Uh, one lists something similar as a, an email contact. And then the third reason that they’re attributing this to an, uh, OpenAI swarm is they’re saying it’s behaving similarly, very extremely similarly to a German wiki agents, uh, incident that they found earlier in the year, uh, where agents accessed 49 of the same files as wiki agents, and OpenAI did confirm that that was their attack.

[00:02:31] **Jenn Gile:** Um, so before we talk about the part B of this that is hot news that just came out like an hour ago, um, Paul, what’s your reactions on this Ruby hack, um, disclosure?

[00:02:45] **Paul McCarty:** Yeah. Well, I mean, I’ve been there since day one. Um, we’ve been identifying this stuff and pulling it into OSM and, um, so I saw the original. I was like right on it when the original 150 were found in May, um, the original batch, and then there was a second wave of about 20, roughly 2,200- Um, and then the most recent article from…

[00:03:08] **Paul McCarty:** Who was that that did the article yesterday? That wasn’t Sec- J

[00:03:10] **Jenn Gile:** Frog. It

[00:03:10] **Paul McCarty:** was J Frog, thank you. Um, they had the total number at about 3,000. Right now I’ve got the total number about 2879, so there’s a could have been discrepancy there, but that’s beside the point. It came in waves and those different waves, the important thing here is that different waves were different, right?

[00:03:27] **Paul McCarty:** So there’s different stuff in them. And so, you know, first you kind of, you see the first wave and it’s like clearly X filling a lot of stuff from UK websites, UK government websites. You’re like, “What the freak? Why is it doing this?” Like, and so then later on, months later when you hear this OpenAI story, and b- because at the time when we were looking at it, all the researchers that were looking at it were like, “This is weird.”

[00:03:53] **Paul McCarty:** This is like, you know, AI is gonna be doing this for some reason. We just didn’t know. And now, you know, hindsight, as they say, is 2020. It makes a lot of sense that if an agent didn’t have access to it, this is the way that it figured out how to get access to the websites. And it, uh, just, and the whole thing makes sense now when it didn’t make a lot of sense then.

[00:04:12] **Paul McCarty:** It’s weird that it

[00:04:13] **Jenn Gile:** makes sense, right?

[00:04:14] **Paul McCarty:** Yeah. Because let’s be clear, like we had a hard time then calling these malicious packages, right? There’s, there’s a couple of them that had payloads in them. There was like a very small single digit number of them that had proper payloads in them, but the vast majority of the rest were not malicious.

[00:04:30] **Paul McCarty:** And so then, you know, what do we call it? A spam campaign. So anyhow, um-

[00:04:35] **Jenn Gile:** Look at this … that- Our, uh, integration with LinkedIn is finally working, so, uh, I can pop up some comments. Hello, Rich, who just popped in here. This…

[00:04:45] **Paul McCarty:** That’s so cool. This is one of my old hockey buddies from Park City. We played, uh, we played hockey together back in the day, Park City I love it

[00:04:52] **Paul McCarty:** what’s up,

[00:04:53] **Jenn Gile:** man? Small world. Uh, we also have a little note from Andrew here. Uh, “Artificial intelligence doesn’t do everything just yet.” That’s true. Um, but here’s the part two of this story. So your buddy Luke over at Truffle, uh- Yeah … the two of you have kind of been chit-chatting the last couple of days and, uh, as he promised us, uh, a blog has gone live, um, kind of connecting how these agents, uh, initially got some access is through a vulnerability that he discovered, disclosed, and helped RubyGems, um, uh, address.

## Truffle Security traces the vulnerability the agents used

[00:05:30] **Jenn Gile:** Uh, uh, before we talk about it, I’m gonna say it’s- Perhaps notable but not surprising that we have not heard anything from OpenAI on this. You know, it’s been not quite a week, um, since this Ruby AI or Ruby Hack blog came out. Um, they’ve been silent. Uh, Luke, you know, I know would’ve liked to have gotten a comment from OpenAI, and it doesn’t seem like that’s happened, so I don’t know.

[00:06:00] **Jenn Gile:** Um, we’d love to see better from them, even if it’s them saying, “Yeah, we don’t think we did it,” which, um, I don’t know that that’s what we would expect right now. So anyway, uh, rant aside, um What Luke over at Truffle has talked about is that the, um… And I’m pulling up here. Um, they found this, uh, vulnerability.

[00:06:23] **Jenn Gile:** I’m looking for what it was called. Uh, you might remember off the top of your head, Paul.

[00:06:29] **Paul McCarty:** Yeah, it was, it was basically a CDN bug. It was, it was a misconfiguration between the RubyGems caching and their Fastly CDN provider. And at the heart of it, um, was the fact that it was, it was… Y- When you, when you hit it, it would just spit back somebody else’s API, which you could then immediately use to say, “Hey, what package…”

[00:06:53] **Paul McCarty:** No. So, so background here is that this is a- for access to RubyGems. So just like NPM and PyPi, you connect to it with the equivalent of a pack or something similar, and then you can push, publish, and, you know, all those things that you can do, un- unpublish, what have you. And so you’d get back somebody else’s API and be like, “List my RubyGems packages,” and you’d get somebody else’s packages back to you.

[00:07:17] **Paul McCarty:** “Those aren’t my packages. Those… I, I didn’t do those.”

[00:07:19] **Jenn Gile:** Whoops.

[00:07:21] **Paul McCarty:** Whoops. Um, so Luke found this in July, and this work is all his entirely, so, like, I’m not taking any credit for this whatsoever. This is entirely Luke, um, Luke Marshall. Um, and super smart cat. I’ve been working with Luke. Um, I’m gonna see him, uh, next week too, actually, in Canberra.

[00:07:37] **Paul McCarty:** But, um, uh, I’ve been working with him and chatting with him for a, a few years now. Very smart cat. But the one- the way that OSM got involved, Jen, is that we kind of worked with the RubyGems team and, and Truffle Security to kind of get us all together in the same room. Because meanwhile, we just had these things streaming.

[00:07:56] **Paul McCarty:** Our own research was pulling these things into OSM- Mm-hmm … and we tr- trying to figure out what the heck is this. And so there’s just… It was really good to have us all kind of in the same virtual room trying to better understand this. The problem is you know who wasn’t in that room, to your point, you said it earlier, OpenAI was not in that room.

[00:08:12] **Paul McCarty:** And, um, and now I have more questions than I’ve got answers, Jen. It’s crazy.

[00:08:18] **Jenn Gile:** Uh, so does Luke. He ends his piece with, uh, a lot of what do we know? What do we not know? Um, again, OpenAI has not confirmed that agents created or published the packages. Um, he mentioned that, uh, the source adds another complication.

[00:08:36] **Jenn Gile:** You know, the fallback was to an embedded key if it finds no token in the response. And even a successful upload by itself wouldn’t establish that it used someone’s credential. Um, so, you know, a little interesting. You know, the packages don’t show continuous exploitation, as you noted, Paul. It comes in waves.

[00:08:55] **Jenn Gile:** Um, you know, and he kind of ends with the same question that I had and you had and a lot of people on the interwebs, uh, have. You know, if a human researcher attempted to do what this agent swarm did- There would be consequences. Um, it does not seem like there are any consequences for a frontier AI company popping other companies, uh, you know, putting malware out there.

[00:09:23] **Jenn Gile:** You know, let’s not, uh, understate the impact of this. The RubyGems team had to shut down new account creation because- Right … it was such a mess. You know, it did… You know, think of it almost like a DDoS attack, right? Like these agents DDoSed Ruby.

[00:09:41] **Paul McCarty:** Yeah. Well, and they, to some extent, they kind of DDoSed all the security teams, you know, us and Socket and everybody else, because they were just pushing…

[00:09:49] **Paul McCarty:** I was sitting there watching one of these pop in every 50 seconds, right? So, like, every 50 seconds we got a new malicious package. Um, and so OpenAI, you cost lots of organizations lots of money and time, you know, with your agents going rogue, and so far you haven’t been held to account. And that’s, you know, I’m, I’m not gonna cuss, but that’s very frustrating.

[00:10:12] **Paul McCarty:** You wasted a lot of people’s time. Not cool. As a paying customer of OpenAI, I’m not happy with you, OpenAI

## Lurves-agent Python typosquats target AI users

[00:10:21] **Jenn Gile:** Okay, next topic?

[00:10:23] **Paul McCarty:** Sure.

[00:10:24] **Jenn Gile:** Sure. Why not?

[00:10:26] **Paul McCarty:** Why not?

[00:10:26] **Jenn Gile:** Um, so this one, uh, came up because a friend of ours… Oh, hold on. We’ll say a quick hi. We have Danielle from Chile. Hello. Uh, hopefully you’re having a great day.

[00:10:38] **Jenn Gile:** So anyway, um, the next topic we’re gonna talk about came up because a friend of ours, Chai, over at AWS, um, published an analysis about some PyPI typosquats that were published recently that are targeting, um, AI, essentially AI users. And these were ones, Paul, that you had already identified. It’s part of a Lurves-agent campaign.

[00:11:05] **Jenn Gile:** Um, we haven’t actually had time to talk about this campaign or why it’s called Lurves-agent. Um, what do you, what do you wanna, I guess, set as the, you know, baseline for why this is interesting? Why talk about these typosquats when there’s so many to choose from?

[00:11:24] **Paul McCarty:** Yeah, right. Because there are so many right now.

[00:11:26] **Paul McCarty:** It’s, it’s the Wild West. It’s the DIY AI vibe hacking Wild West right now. First, let’s talk at a high level about naming, right? Sometimes you name… There’s two reas- there’s two ways you name things. One is that you look at it creatively and you come up with a cool name, which is something we’re gonna talk about hopefully next week when we unveil our latest research on some malware that we found that we’ve named.

[00:11:50] **Paul McCarty:** I’m gonna… Is that o- Jen, is that okay for me to, like-

[00:11:52] **Jenn Gile:** Um, I think you should share it 'cause I think it’s hilarious.

[00:11:57] **Paul McCarty:** So we found some new malware. It’s, it’s probably North Korean. I’m still working on the official attribution. I mean, I can guarantee it’s North Korean, but I don’t have the attribution data to, to fully back that up right now.

[00:12:10] **Paul McCarty:** So I’m saying it’s DPRK like. But basically it’s taking features of O- OtterCookie and it’s taking features of BeaverTail and it’s just a much, much leaner, stripped down version. Um, doesn’t actually steal crypto the way that the OtterCookie, um, and BeaverTail do, but it does some of the other stuff. It’s got a clipboard stealer.

[00:12:28] **Paul McCarty:** Anyhow, I’m getting off topic. I, because it was a, it was a sc- it was a leaned out, stripped down version of OtterCookie, I thought, “What is, what is a rougher, crappier version of an otter?” And I thought a weasel. And I thought here in Australia, “What’s a crappier version of a, a cookie? A bikkie, a biscuit.” And so I thought, “Oh.”

[00:12:51] **Paul McCarty:** Weasel Biscuit. So we, the new malware is named Weasel Biscuit, and we’re sticking to it. Um, uh, we’re going- I

[00:13:00] **Jenn Gile:** don’t know how we got here. How did we get here?

[00:13:02] **Paul McCarty:** Right. Right. Yeah. Well, we got here because this is what… I’m YOLOing. That’s why. I like doing it. 'Cause I got some friends, I got Rich and some other people listening, I gotta be, I gotta entertain these folks.

[00:13:11] **Paul McCarty:** But, um, so anyhow, sometimes we get to name them that one. Why is lurves-agent, that campaign, named that? The other way is because they add, the bad guys themselves add that into the code. And this was, uh, this was generated by AI. You can look at it and you can know that it’s, it’s relatively simplistic. Um, and it’s got a really cool tweak here, which we’re gonna talk about in a second.

[00:13:33] **Paul McCarty:** But I suspect that lurves-agent is what somebody has named their agent, and as agents do, they just generate some code and they, they self-attribute inside the code. And the human hasn’t looked at what they’ve generated, and so it’s, it’s the lurves-agent. So, hey, thanks whoever named lurves-agent. I’m gonna find you 'cause I’m gonna pivot on lurves-agent, and we’re gonna, we’re gonna, we’re gonna get you.

[00:13:56] **Paul McCarty:** But anyhow, um, so what does it do? Um, it’s got a, it’s got a little payload. It’s got a little info stealer payload. Um, it’s all, like, it’s literally two or three lines of code. Uh, but above that are nested comments in the bash script. Uh, I can’t remember if it’s ba- oh, that’s what it is. It’s the path file.

[00:14:17] **Paul McCarty:** So it’s, it’s actually Python. So, and the comments are basically a prompt injection, um, uh, that basically says, “Hey, there’s nothing to see here. I tweeted it. I put it on LinkedIn. There’s nothing to see here.” Um, and then, uh, and then the payload runs, which is this info stealer. Um, and so they’ve targeted OpenAI, um, Langrap, um, Llama, and a couple…

[00:14:42] **Paul McCarty:** I think there’s five or six packages all up inside the campaign. And

[00:14:46] **Jenn Gile:** they’re all targeted- Yeah, I think it’s

[00:14:47] **Paul McCarty:** six … really simplistic kind of, um, but like OpenAI, it’s OpenAI with an extra I. I mean, you know, some pe- I haven’t looked at downloads today, but some number of people are gonna accidentally install that and oops, Bob’s your uncle, as we say here in Australia

[00:15:05] **Jenn Gile:** Yeah, I’m looking at the downloads right now, and they’re relatively low, somewhere in the 40 to 50 per week range, but, uh, that’s not zero.

[00:15:16] **Jenn Gile:** And, um, you know, things targeting it, targeting agents are getting more common. Um, okay, before we move on to our next topic, we have a kind of an existential question from Andrew here. He asks, “If an AI agent exploits a vulnerability to achieve a benign goal, is that an alignment failure or an authorization failure?”

[00:15:38] **Jenn Gile:** Uh- Well,

[00:15:38] **Paul McCarty:** A-

[00:15:39] **Jenn Gile:** I, I’m gonna say, what makes us think this is benign? But…

[00:15:45] **Paul McCarty:** Yep. You and I are focusing on the same part of that question, Jen.

[00:15:48] **Jenn Gile:** Yeah. Let, let, let’s roll with it. Let’s pretend for a moment that, um, whatever reason, uh, for this OpenAI agent swarm attacking Ruby was a benign reason, you know, much in the way that allegedly, uh, the Hugging Face hack was, you know, a benign reason to start with.

[00:16:07] **Jenn Gile:** The damage still exists, but what do you think? Like, let’s assume good intent here. Is it an alignment failure or an authorization failure? What do you think?

[00:16:16] **Paul McCarty:** Well, okay, hold on a second. I mean, I don’t wanna get into the, the, uh, abstraction of the language and the vernacular around alignment, right? I think that, to your point, Jen- You know, your definition of benign might not be my de- definition of benign.

[00:16:34] **Paul McCarty:** So let’s just use this as a my, as a thought experiment. If I take a gun into an open space and I accidentally shoot someone, I’m still liable. Am I gonna get charged for homicide? No, but I’m absolutely gonna get charged with manslaughter. So I think just because… And, and alignment kind of assumes that there’s, like, some sort of moral compass or an understanding, and that’s not the case here.

[00:16:58] **Paul McCarty:** Agent’s job is to make us happy as much as possible, which is why they’re constantly bypassing the guardrails that we explicitly tell them. Like, in my, in my skill, I’ll be like, “Do not ever, ever, ever, ever, ever put a database credential in a .env file or in source code.” And as soon as your agent hits problems with row-level security or other issues, what does it do?

[00:17:23] **Paul McCarty:** It puts it in source code because its job is to make you happy. And so this idea of alignment, I think, is, is trying to connect too much to, like, like, a moral compass and context, and I don’t think that’s, I don’t think that’s the case here. Um, I think that the agent said, "I need to get access to the internet.

[00:17:42] **Paul McCarty:** How can I do it? Oh, look, RubyGems. I have r- access to RubyGems," because the developer said, “Oh, you need access to RubyGems. Let me use RubyGems to go and, you know, exfil the data I need from the websites that I need.” Um, and also pop a few, 'cause there were some live payloads in there as well, so. Sorry, that’s a, a ranty rant, but-

[00:18:01] **Jenn Gile:** Yeah, I mean, it’s tough.

[00:18:03] **Jenn Gile:** Like you said, um, uh, these tools are built with their first rule being do what the user wants rather than the first rule being something around safety and avoiding harm. And are we gonna continue to see this stuff even if the right intent is there from the people managing them? Yeah, probably, because as we saw with the, you know, full, uh, uh, postmortem on the Hugging Face incident, it was a situation where it escaped the sandbox in an effort to complete the task.

[00:18:43] **Jenn Gile:** So there was probably a task and not enough guardrails involved. That’s, that’s unfortunate.

[00:18:53] **Paul McCarty:** Yeah, 100%. And I mean, there, there’s lots of issues with the Hugging Face issue too as well, the fact that incident response has been done, you know… Like, it’s, it’s an AI company. It’s not a incident response t- team.

[00:19:05] **Paul McCarty:** So there’s just- Mm-hmm … you know, you know, you just have to question the whole thing, right? Um, and this connects to what we were saying with, you know, OpenAI’s… You know, there’s just gaping holes in the story right now- Yeah, use the CDN issue, but it doesn’t… What, what Luke and I know about that doesn’t match what you guys are saying, so…

[00:19:24] **Paul McCarty:** And we’re never gonna get an answer. That’s the problem, Jim. We’re never gonna get an answer because these people are a black box, um, and that’s a problem.

## A typosquatted Claude site delivers signed Mac malware

[00:19:31] **Jenn Gile:** Yeah. Well, on the next topic, and by the way, there was no intent to make this the AI episode, but it is another AI-related topic. Um, you, uh, DM’d me a website earlier, and let’s be clear, it wasn’t like, “Hey, go click on this website.”

[00:19:47] **Jenn Gile:** So I’m gonna share this website in the chat and, like, please let’s all agree we’re not gonna be stupid and go click on things, because this is, this is the typosquatted website. Um, so I’m gonna… It’s [claude-desktop.com](http://claude-desktop.com) for those of you listening, and I’ll paste it in when I can type a little bit more of a disclaimer around it of like, “Please don’t go download Claude from this,” 'cause you will not be downloading Claude.

[00:20:11] **Jenn Gile:** What you will be downloading is the latest Mac malware. And Paul, as you, uh, explained to me, you know, historically this malware has been distributed through kind of a click fix type thing. But in this case, um, you’re downloading a DMG file. They’ve signed it. It looks legit. You think that you’re downloading the Claude, uh, desktop app, um, but surprise, you’re downloading Mac malware.

[00:20:39] **Jenn Gile:** Um- Yeah … how did this get on your radar? Was this our buddies over at Jamf that found this?

[00:20:44] **Paul McCarty:** Uh, may- yeah, maybe. I, I didn’t explicitly get their okay to say it, but I think it’s, you know, it’s on the public listen page, so sure, yeah. Um, the… Yeah, so I mean, it’s… Uh, something to understand too is these Claude and OpenAI installers are just really particularly effective because Claude, the CLI, for example, this is pretending to be Claude, the, the installer, the desktop thick client version of it.

[00:21:11] **Paul McCarty:** But-

[00:21:12] **Jenn Gile:** Right …

[00:21:12] **Paul McCarty:** in either case, the way to offi- the official described way to install these tools has changed a lot over the last year. And so because of that, different ways to… People are kind of open to this idea, “Oh, I’ll just install this way, I’ll just install it that way.” So they’re just a little bit looser about how they’re installing this.

[00:21:30] **Paul McCarty:** So for example, this Claude CLI, they wanted you to install it via NPM, and then it changed, and now they want you to do the classic- Pull it in via curl and pipe it to bash ridiculousness. But because there’s un- you know, there’s, uh, there’s, there’s different ways to install these things, it opens you up for this, and this is just a really well done typosquat website.

[00:21:53] **Paul McCarty:** You know, [claude-desktop.com](http://claude-desktop.com) is delivering a signed DMG, so when you install it, you know your Mac is gonna come up and say, “Hey, this is signed. You should be good to go.” And you pop it in and, you know, you know, boom, you’re compromised. So we’re gonna escalate this one internally with all of our customers and with our community because it’s just so powerful.

[00:22:14] **Paul McCarty:** It’s just working really, really well right now, unfortunately. Um, and here’s the thing is, I traditionally, here’s the last thing I wanna say. Traditionally, Macs have been kind of left out of the, the malware info stealer ransomware world, right? Like that we’ve just kind of got a pass historically. That’s just not the case right now.

[00:22:32] **Paul McCarty:** Um, Jen and I are seeing from a DPRK perspective, almost 70% of the compromised hosts are MacBooks, right? Like bad guys are going after Macs like no other time before, like this, it is on the-

[00:22:49] **Jenn Gile:** And let’s be clear, it’s not because Macs are less secure. Yeah. It’s because developers are more likely to be using Macs

[00:22:57] **Paul McCarty:** 100%.

[00:22:58] **Paul McCarty:** Well, and also too, Macs have now become the popular de facto client- It’s the popular, yeah … even if you’re not a developer. Yeah. I mean, if you’re in marketing, right, if you’re in publishing, you’re, you know, if you’re in HR, you’re probably got a Mac, right? So, um, you know, they’re killing, you know, a bunch of birds with one stone.

[00:23:14] **Paul McCarty:** Um, and the reality is-

[00:23:16] **Jenn Gile:** Yeah, and apparently it’s the, the divisive choice for most startups, which are less likely to have a robust security team. So there’s a lot of reasons to target people who use Macs.

[00:23:25] **Paul McCarty:** 100%. 100%. But, um, what was the last thing I was gonna say about this? I got, um, I got knocked off there.

[00:23:31] **Paul McCarty:** Um, oh boy. Oh well, I lost it.

[00:23:35] **Jenn Gile:** It might come to you. Maybe. Maybe, maybe not. Um- Maybe,

[00:23:40] **Paul McCarty:** maybe

[00:23:40] **Jenn Gile:** not … you know, before we move on to our last topic, I’m gonna say I’ve done a little bit of, uh, content recently on our LinkedIn and on, uh, our other socials focusing on the fake font VS Code task.json attack vector.

[00:23:57] **Jenn Gile:** Ha-ha, I’m gonna talk about DPRK and I didn’t mean to. Sorry. Um, I’m actually not gonna talk about that specifically. No, it’s fine. But what I’m gonna say is, um, the number of people engaging with that content who weren’t aware of this attack vector is high. And so that tells me this is a thing we need to continue talking about.

[00:24:18] **Jenn Gile:** Uh, it’s not the only way you can get compromised, but this is like a really easy thing to spot. And I wouldn’t say like a super easy thing to prevent, but you can go in and you can turn off by default tasks auto-running. Uh, uh, y- and you should. There’s no… You don’t need it to auto-run.

[00:24:39] **Paul McCarty:** That’s true. Also, if you install any extensions, they’re probably gonna require that those tasks runs at least in, at install time.

[00:24:47] **Paul McCarty:** So just be aware just 'cause you turn it off, there’s gonna be a bunch of things that unfortunately will prompt you to turn it back on. Just be aware

[00:24:53] **Jenn Gile:** of that. Much like the NPM life cycle scripts

[00:24:57] **Paul McCarty:** Yep. I mean, if they gotta install stuff, they’re gonna install stuff, right?

[00:25:00] **Jenn Gile:** Yeah. But I did a quick search on GitHub, uh, this morning.

[00:25:04] **Jenn Gile:** I was talking to somebody, uh, which segues into our next topic, and I’m not gonna say anything more about it because it’s confidential. But I was talking to somebody about this campaign, and I just did a quick search for that fake font file, and there’s over 1,600 instances of that malicious file on GitHub right now.

[00:25:23] **Jenn Gile:** So this is- Yeah … very much a real problem.

[00:25:26] **Paul McCarty:** Yeah, the, the fake font thing has just blown up. Like, um, uh, OSJ, um, I don’t know his real name, but on Twitter, um, software security guy and, um, software supply chain guy, he found several of them, you know, four or five accounts. And I wrote back, and I wasn’t trying to be a jerk when I did it, but I was like, “Yeah, we got over 3,000 of these in OSAM.”

[00:25:49] **Paul McCarty:** And he wrote back, “Holy beep.” Not realizing that there was this much of it out there in the wild, so.

[00:25:55] **Jenn Gile:** All right, we got another question. Uh-

[00:25:58] **Paul McCarty:** Uh-huh …

[00:25:58] **Jenn Gile:** if signed malware is becoming this effective, are code signatures still a meaningful trust signal? Uh, gosh. I mean, better to sign than not sign, but s- uh, not by itself.

[00:26:13] **Jenn Gile:** Yeah.

[00:26:15] **Paul McCarty:** Yeah. I mean, the, the answer, the simple answer to the question is yes. Signed, you know, uh, uh, installs are important. The vast majority of them, you know, are legit. I, I think that, you know, and I don’t know if in your, in your MDM tools, for example, in Jamf and some of these tools out there, if you can like, I think you can, but I’m not an MDM admin, so I wanna be careful.

[00:26:38] **Paul McCarty:** I think what you can do is you can write rules and policies around who things are signed by, right? So you can basically, you know, create some guardrails around that. But, um, no, I mean, you know, signed installers are important. The problem is that bad guys, like everything else, are figuring out a way around, around it.

[00:26:55] **Paul McCarty:** So I’m sure happily with that- Yeah.

[00:26:56] **Jenn Gile:** Well, it’s like some of the supply chain attacks- … some of the attacks … we saw earlier in the years where the pipeline is what was compromised. And so the things getting published went through a trusted publishing mechanism Uh, yeah, they can always find a way

[00:27:12] **Paul McCarty:** Yeah. But, you know, those ones that find a way, they’re just like, you know, it’s a relatively small number.

[00:27:17] **Paul McCarty:** So, like, li- listen, this is an important control. We shouldn’t give up on it, and I’m sure Apple will double down on it and make it better, faster, stronger, even better. Yeah But the reality is side installers are an important component of our control set.

[00:27:30] **Jenn Gile:** Okay, we’re gonna take another question 'cause I think it’s an important one.

[00:27:33] **Jenn Gile:** Uh, should we treat AI agents as untrusted users by default rather than trusted software? 1000% yes.

[00:27:40] **Paul McCarty:** Um- 1000%. The… I have so much to say. Go. Sorry, Jen, go ahead.

[00:27:45] **Jenn Gile:** Uh, I was just gonna say, uh, one of the talks I’ve been giving this year about malicious AI skills hijacking agents, we’ve just seen, um, too many examples of agents being easily weaponized, uh, to do things that you didn’t want them to do.

[00:28:02] **Jenn Gile:** And so even if you’re not worried about, you know, OpenAI’s rogue band of agents, which probably you should be worried about that, but the more realistic problem is that your own agent, uh, is gonna do things you don’t want it to do. And so, uh, like least privilege, uh, there’s the Trail of Bits, uh, sandboxing, uh, hardening guide.

[00:28:25] **Jenn Gile:** Like, there’s lots of things that you should be doing with your agents to make sure that they can’t go do things you don’t want them to do. Paul, uh, opening the floor for you We,

[00:28:35] **Paul McCarty:** we absolutely should be treating them as untrusted users. The problem is, what is the first thing that we do with our agents?

[00:28:41] **Paul McCarty:** We just hand them a bunch of like unscoped credentials say, “Hey, have at.” And even worse, most of us are lazy humans, we YOLO it. I don’t, but like many of us do. And, you know, like it’s just… It’s like everything else, like, you know, we all say that we wanna pay our taxes, but we really don’t wanna pay our taxes.

[00:28:59] **Paul McCarty:** And the thing is, dear, that, you know, we say that we, you know, need to treat these things as untrusted, but we all give them way more access than we should. So, yeah. That’s-

[00:29:08] **Jenn Gile:** Yeah. We’ve gone ahead and made the wrong thing the easy thing to do with agents, and I get why, but it means that with, as with many best practices, you have to opt in to doing the right thing, and-

[00:29:26] **Paul McCarty:** Connect… Li- listen, connecting your password vault or your credential vault to your agents is more painful than it should be, right? And, like, the, uh, the, the companies, the frontier companies, and I’ve said this before on the show, haven’t even tried to make it… You know? Like, at least GitHub has GitHub, you know, secrets, and they have a way to kind of, you know, allow you to use credentials inside of your GitHub actions in a way that’s kind of secure, relatively secure.

[00:29:56] **Paul McCarty:** OpenAI and Anthropic haven’t done any of that, right? And that’s crap. Um, they re- they know that people are gonna do this. They know that, that people are gonna give their agents, you know, lots and lots of credentials in the form of PATs and all kinds of other stuff. They should have come up with themselves.

[00:30:12] **Paul McCarty:** Um, they’re certainly making a lot of money right now, right? I know they’re in a, they’re in a rut- Yeah … because, you know, they are AI companies. But anyhow, they should have come up with a, they should have come up with a solution to this themselves. This shouldn’t be something I gotta go and find some point solution, some open source DIY point solution for.

[00:30:30] **Paul McCarty:** That’s not, that’s not cool.

[00:30:31] **Jenn Gile:** That’s not great, yeah. There’s, there’s more that could be done. Okay, uh, last topic. You put this one on the list, so why don’t you, uh, introduce it and talk about what you wanna, what I know.

## Law enforcement takes PolinRider and DPRK seriously

[00:30:41] **Paul McCarty:** Yeah, I mean, I just… You know, Jen and I were in Europe last week for the, for the Team Cymru, um, Underground Economy Conference, which is an amazing thing.

[00:30:50] **Paul McCarty:** It was four days, so it’s long. Oh my gosh, it’s long, and it’s in this town called Strasbourg, which is hard to get to via planes. But, um, as an American or Australian, just used to being able to fly everywhere, but couldn’t fly into Strasbourg, at least from where we were coming. Anyhow, um, listen, most of the event is TLP red, so we can’t go into, like, what was talked about there.

[00:31:09] **Paul McCarty:** But Jen and I did have a talk there, um, around North Korea. Uh, it was very well received. And the thing I wanted to talk about was the fact that traditionally what we’ve heard a lot of from enterprise is that, “Oh, North Korea, you know, they’re immature, and they just…” And I see all these ridiculous things because they’re so singularly focused on ransomware, right?

[00:31:27] **Paul McCarty:** Their EDR vendors have just got them all keyed up via FUD that ransomware is the number one thing they should be worried about. And what was- What I took away from last week was that we, we- the feedback we’ve gotten is that enterprise government law enforcement is absolutely taking DPRK seriously now.

[00:31:47] **Paul McCarty:** In particular, they’re taking PolinRider seriously just because it’s just everywhere. Mm-hmm. Um, and banks, financial institutions are aware of it now, which is great. We just need to keep talking about it because this is the… Just to be clear, this is the world’s largest software supply chain attack.

[00:32:01] **Paul McCarty:** PolinRider I’m talking about. World’s largest software supply chain attack that, you know, has been unfortunately going under, you know, riding under the radar, um, too much and we wanna change that. So it was, it was really, you know, I was glad to see people taking it seriously last week.

[00:32:18] **Jenn Gile:** Yeah. Mm. Lots of really good conversations.

[00:32:21] **Paul McCarty:** And I’m wear- I’m wearing my shirt.

[00:32:22] **Jenn Gile:** I see that.

[00:32:24] **Paul McCarty:** Yeah. Yeah.

[00:32:25] **Jenn Gile:** All right. We’re at about half an hour. I think it’s time to wrap it up. Um, this has been- I agree … a good talk. Uh, I don’t think I have anything else to add. Do you?

[00:32:36] **Paul McCarty:** Yeah, not really. I mean, we’re doing this next week, um, w- hopefully in the regular spot.

[00:32:41] **Paul McCarty:** So, um, thanks everybody for listening. We really appreciate it.

[00:32:44] **Jenn Gile:** Yeah, take care.

[00:32:47] **Paul McCarty:** Ciao.
