BLOG
Tensorlake SDK hit by a Mini Shai-Hulud copycat, fake interview repo plants a rogue .npmrc, and 42 malicious crypto gems on RubyGems
By cb482791-4ef1-4762-96ad-b0ca4bdd538e · The OpenSourceMalware Show is available on YouTube, LinkedIn, and as a podcast.
This week we talked about:
Tensorlake SDK compromise: The npm SDK for Tensorlake, a tool for building and operating AI agents, was compromised with two malicious files. A setup.mjs file fires through a preinstall hook and launches the payload with Bun, and math_symbol.js carries a credential stealer and self-propagating worm. It is at least the second attack built on the open-sourced Mini Shai-Hulud worm, following the August attack on keyv and cachable. We discuss why this well-known pattern should have been caught by registry scanning, and what the lack of impact suggests about the attacker.
Rogue .npmrc in a fake job interview: A new attack follows the Contagious Interview playbook but is not yet attributed. The repo a candidate clones quietly drops a custom .npmrc, so a later npm install resolves a package from a Chinese npm mirror instead of the public registry. We also look at packages with no malicious payload on their own that only become malicious when combined through dependencies, and why scanners miss them.
Malicious crypto gems on RubyGems: OpenSourceMalware's automated detection flagged 42 malicious gems published by a single account calling itself Ghost Dev. They target crypto and Web3 developers through typosquats, brandjacking, and plausible utility names. Installing the gem runs a native extension build script that sleeps for 20 to 40 minutes, then either opens a reverse shell or installs a wallet theft kit posing as a tool called Wallet Guard. We also cover why a Python payload inside a Ruby package is a useful signal, and how slopsquatting gets more effective as AI tools hallucinate dependencies across ecosystems.
Resources #
- (report) [tensorlake threat report](https://opensourcemalware.com/npm/tensorlake)
- (blog) [New npm Worm Hits 400+ Packages Including Keyv, Cachable](https://opensourcemalware.com/blog/new-npm-worm-keyv-cachable)
- (blog) [Malicious Crypto Shell Packages Target RubyGems](https://opensourcemalware.com/blog/malicious-crypto-shell)
[00:00:00] Jenn Gile: Hello. It is Thursday, October 8th. Um, we have a couple topics on the agenda, but before we dive in, what's up, Paul? What's new?
[00:00:13] Paul McCarty: Good question. What is new? Um, just, you know, enjoying being home for a few months. I think that's, um, nice. You're, you're taking one for the team and you're going to the SANS thing, so thank you for, for doing that.
[00:00:27] Paul McCarty: Yeah. Although, I really, really, really wanted to go to [00:00:29] Jenn Gile: that travel- I was thinking about the travel schedule recently, and I was like, "Oh, I just got done with a battery. Why am I doing this again?" But I'm excited for the, the things that I have coming up
**[00:00:40] Paul McCarty:** Yeah, you got a couple really, really cool things coming up.
**[00:00:43] Paul McCarty:** And I forgot you were going to LASCON, so that's, that's super dope.
[00:00:46] Jenn Gile: Yeah, so, uh, for anybody who's going to the SANS, uh, summit next week in Virginia/Washington DC, come say hi. I'm gonna be giving a talk on, um, PolinRider. And then, uh, at the end of the month I'll be in Austin at LASCON giving a talk on malicious AI skills.
[00:01:08] Jenn Gile: Uh, I really like LASCON. I was, um, looking at their webpage, website, uh, you know, kind of writing up my post to say, "Hey, you know, I'm gonna be there," and their website says they get about 400 people a year. And honestly, it's one of those conferences that, like, if you had told me 400, I wouldn't have believed it.
[00:01:26] Jenn Gile: It either would be more or less, but like, it's just... I don't know. They have a ton of tracks. Um, people from all over the country travel to it. Like, it's just a really unique conference. So, uh, if you haven't gotten your ticket yet, they are still available. They're a little pricey if, um, you're paying outta pocket last minute, but if you can get your employer to pay for it, you should 'cause the content's great, the networking's great.
[00:01:52] Jenn Gile: Uh, they put on a really nice conference. [00:01:55] Paul McCarty: The show from, uh, sorry, the shirt, the swag, the shirt from the 20- I guess it would've been 2024 when they did the upside down, um- Yeah ... the, the Stranger Things- I didn't get
**[00:02:06] Jenn Gile:** that shirt, but I know which one you're talking about.
**[00:02:08] Paul McCarty:** I, I wore it a couple days ago. It's just such a great shirt.
[00:02:12] Paul McCarty: W- great swag. Oh, I have the challenge coin right here. There we go. There we go. There we go. There you go.
[00:02:18] Jenn Gile: Oh, very nice. [00:02:21] Paul McCarty: And then the upside down bull, because they always have the bull. And I did ride the bull. The bull. Yeah.
[00:02:26] Jenn Gile: Uh, I enjoy going and watching who does ride the bull. That's the best part about the happy hour, is to see who, who decides to bull ride.
[00:02:36] Paul McCarty: I definitely bull rode, and watching the video back, I'm just so embarrassed. It's, like, painful to watch it. Like, it's so slow, and at one p- one point m- my tummy pops out because you're like this. I just, the whole thing is so cringe.
**[00:02:53] Jenn Gile:** Pretty cringe.
**[00:02:54] Paul McCarty:** Oh
**[00:02:54] Jenn Gile:** my God. I don't know. I feel like, uh, that might be part of growing up.
[00:02:58] Jenn Gile: Somebody, you know, you gotta at some point if you have an opportunity to ride the bull. I probably did it in my 20s at some point, uh I'm not gonna do it now 'cause I will hurt myself. Okay. I know. Anyway, yesterday-
[00:03:10] Paul McCarty: So many, so many jokes, so many jokes in there that we're just not gonna like, we're not gonna
[00:03:13] Jenn Gile: touch Not gonna...
Tensorlake SDK hit by another Mini Shai-Hulud copycat worm #
[00:03:14] Jenn Gile: We're, we're, we're gonna roll on. We're gonna talk about- Keep going ... Tensorlake. Um, yeah, as I was, uh, winding down last night, um, we saw Tensorlake get compromised. Tensorlake, uh, it's, is their SDK is what was compromised, so it is, uh, used for building and operating AI agents, and, um, there's a couple things to know about this.
[00:03:40] Jenn Gile: Uh, first, it is a pretty widely used package, so the, if you're a Tensorlake user, um, definitely, uh, you know, make sure you're not using the compromised version. It was taken down relatively quickly within a couple of hours, I think. Uh, but this was, uh, the second time, I think, second or third time we've seen an attack that leveraged the open sourced Mini Shai-Hulud worm from earlier this year.
[00:04:15] Jenn Gile: Um, it's very similar to the attack that happened in August that targeted Jared Wray's projects. So that was, um, a pretty substantial one. It, you know, hit 400 or so packages 'cause he maintains a lot of things, and it had a little bit of success on the worm-like behavior. Uh, I'm not seeing any success on this iteration's worm.
[00:04:39] Jenn Gile: Have you seen, heard anything? [00:04:41] Paul McCarty: No. I mean, I've seen it described. The only thing I've seen really is I've seen it described as not having any real impact though. Um, yeah.
[00:04:51] Jenn Gile: So that's good news. Um, I'm gonna go ahead and drop our threat report on it in the chat. Tensorlake I'm just
**[00:05:02] Paul McCarty:** going through... Sorry,
**[00:05:04] Jenn Gile:** Jenn Continue.
[00:05:05] Paul McCarty: I was just gonna say, uh, you know, I was just going through the list of stuff that it exfills, the specific, um-
[00:05:12] Jenn Gile: It's real similar to what we've seen from the- Yeah ... previous iterations. Um, I'm sharing our blog that we published in August about the Cacheable Keyv, um, compromise, that was the bigger version of this.
[00:05:27] Jenn Gile: 'Cause it's, it's not identical, but it's very similar. [00:05:32] Paul McCarty: I don't know if the, um... I'm looking at, it's also, it also specifically looked for the Bitrise_IO variable, which, um, I don't know if that was in the last one. That might be new. That might be new. There's always... Yeah, I mean, whenever you look at these, there's always one or two things that are added.
[00:05:47] Paul McCarty: But, I mean, I think what we're driving at here at some level, Jenn, is the fact that this, you know, this is kind of... I don't wanna say it's a nothing burger, 'cause it's not. I mean, it's, it's real. But it looks and feels like the last several versions of this, right? And I think that people have, you know, over the course of the, the MIASMA and the Mini Shai-Hulud iterations, you know, have worked on some form of, excuse me, um, you know, way to, to deal with this.
[00:06:17] Paul McCarty: And so I think shields are up. I, I, I guess that's what I'm trying to say. Bringing back a term from 2024, shields are up and, um, and it appears those shields were, you know, I think mostly successful.
[00:06:30] Jenn Gile: Yeah. I think it's probably a combination of better defense and, um, I'm gonna go out on a limb and make some, uh, uh, I would say, uh, assumptions here, not proven.
[00:06:44] Jenn Gile: Um, I don't think we're dealing with a very sophisticated threat actor. Uh, this reads like they used the open source form as a template, probably had access to some LLMs and some automation, and, uh, somehow managed to get access to the GitHub repository for this, uh, Tensorlake project. Um, I think it took them a little bit of time to detect it, but it's not clear how they got, uh, in, much in the way that it's not clear how the attackers got in, uh, back in August.
[00:07:21] Jenn Gile: So there's probably some combination going on here of using AI to find a reasonably popular open source project that has a vulnerability in it somewhere, um, combined with, you know, a little DIY malware template. But I think just based on the, you know, lack of panic, which is a good thing, I don't think we're dealing with somebody very sophisticated here.
[00:07:54] Paul McCarty: Yeah, I think all signs point to low sophistication for this one. Um, and, uh, you know, they did use a custom, um, you know, domain. So, uh, it's following the form and function of some of those, you know, April to June, um, patterns. Uh, but I wanna take this opportunity... Wait, I wanna look right down the... Hey, GitHub, npm.
[00:08:24] Paul McCarty: I thought you guys were scanning npm packages. What's going on, homies?
[00:08:29] Jenn Gile: Yeah, I guess what I'll say there is this is definitely following a really clear playbook. Um, the malicious version contained two files, uh, in addition to the regular, uh, content that you would expect in the package. That included a setup.mjs, which fires through a pre-install hook.
[00:08:50] Jenn Gile: Oh, isn't that one of the things we all know to look for at this point? That's what any scanning, proactive scanning should have caught. And then, uh, so that pre-install hook, uh, launches the payload using Bun. Again, fairly, um, well-known pattern at this stage. And then we have a math_symbol.js file, which again, similar to what we saw in August, slightly different names, uh, that contains a credential stealer and self-propagating worm.
[00:09:21] Jenn Gile: So yeah, there's some pretty clear signals with this that proactive scanning- Likely should have caught
[00:09:29] Paul McCarty: Yeah. I'm, I, I will go a step further and proactive scanning likely doesn't exist.
**[00:09:35] Jenn Gile:** Yes.
**[00:09:36] Paul McCarty:** Doesn't exist as- That would be what
**[00:09:37] Jenn Gile:** follows ...
**[00:09:39] Paul McCarty:** as a functioning thing, as a functioning function. You know, it's interesting- Okay
Fake job interview repo plants a rogue .npmrc to resolve a hidden package #
[00:09:45] Paul McCarty: because... Oh, sorry. I was gonna, I was gonna go off topic today 'cause we're YOLOing it, right, a bit. Is that okay?
[00:09:51] Jenn Gile: Sure. I was gonna move on to the RubyGem topic, but if you have something that's, uh, worth talking about now, let's start there.
[00:09:57] Paul McCarty: I wanna do both obviously, but um, I think in anticipation of the npm v12, you know, changes, we, we saw bad guys even before that came out.
[00:10:06] Paul McCarty: We saw bad guys like, you know, pivoting and, and coming up with really unique ways and, and that continues. That trend continues. I'm seeing, every day I'm seeing kind of unique attempts. So something that I saw yesterday, I haven't even had a chance to write this up, but yesterday, excuse me, what we saw is we saw a Contagious Interview style attack, which is a combination of a GitHub repo and a npm package.
[00:10:29] Paul McCarty: Um, and if I'm not mistaken, the GitHub repo required the npm package. But here's what happened is- Yeah ... if you looked at, and this was in th- a public npm package, if you looked in its package.json manifest, it called out to this package that wasn't in the public, uh, uh, registry. And so here's what happened.
[00:10:49] Paul McCarty: The GitHub repo that you downloaded and you cloned beforehand as part of this interview process, and there's no s- yet I've n- seen, Jenn, just to be clear, I have yet to see data saying this is genuinely a DPRK Contagious Interview thing. I, it just, it looks and feels like a, like an interview process. Well, it is.
**[00:11:07] Paul McCarty:** It's following the kind of GitHub,
**[00:11:09] Jenn Gile:** um- It's following the playbook, whether it's DPRK or not, it's not attributed. Yeah. Yeah.
[00:11:13] Paul McCarty: I'll, I'll do more and I'll circle back next week and I'll have an answer there. But in the meantime, what happened is, 'cause you'd cloned the GitHub repo earlier, what it did is it did this really sneaky thing where it dropped an npmrc, a custom npmrc into the, to the repository.
[00:11:30] Paul McCarty: And then when you, when later on it did the npm install and it got to that line, which if you don't have the npmrc, if you're just talking to registry.npmjs.com- That file doesn't exist. You think, "Oh, it must be an internal, you know, a private, um, package." Turns out that npmrc token they dropped in there then points you at a different registry where it does resolve, right?
[00:11:56] Paul McCarty: And it was one of the Chinese ... By the way, like all this work that I did last year on the Chinese mirrors is still coming to- Mirrors, yeah ... yeah, still coming to fruition because that's exactly what this was. This was pointing at one of the Chinese npm mirrors, npmmirror.com, and very subtly named, um, does what it says on the tin.
[00:12:16] Paul McCarty: But I just thought that was a really unique way of doing it, right? Like, especially if you know that you're gonna own the whole workflow, and I think that's the important thing here is that a lot of people when they look at an npm package, they think about it, and like all the security scanning companies do this, they kind of oversimplify what's happening behind the scenes.
[00:12:34] Paul McCarty: They think somebody going there, what's gonna happen? The problem is a lot of these npm installs, or the equivalent in, in pip and other places, happen as part of a constructed workflow. Contagious Interview is a really good example of that, but there's other versions of this. So other things happen beforehand that are the dependencies and the foundation that then that can
[00:12:53] Paul McCarty: And we're seeing this in other places too. A really good example, and Aikido and all the other scanners will see this too as well, we're seeing a lot of packages right now that don't have a malicious payload. W- and we talked about this a little bit in last week's episode, where you have to combine two or three npm packages that, and they all call each other in dependency structure.
[00:13:11] Paul McCarty: And then the three of those will combine to give you that payload. Um, and those are just some really kind of simplistic ways. So first, npm GitHub, you're not doing a very good job scanning based on the really simple pattern matching that we already know about, like these, you know, these existing Mini Shai-Hulud patterns.
[00:13:29] Paul McCarty: And y- you don't even have anything for this other stuff, which is actually much more, you know, productive. And scanners aren't finding these things, like the software supply chain firewall scanners aren't finding these, and, um, a lot of times the scanning companies aren't, aren't labeling these things as malicious because guess what?
**[00:13:45] Paul McCarty:** There's no malicious-
**[00:13:46] Jenn Gile:** By
**[00:13:46] Paul McCarty:** itself it's not
**[00:13:47] Jenn Gile:** malicious ... there's no exploit. Yeah. Yeah.
**[00:13:48] Paul McCarty:** You got to combine it. It's like the, the, the Voltron, right, from
**[00:13:52] Jenn Gile:** the movie? I know. I'm
**[00:13:53] Paul McCarty:** en-
**[00:13:53] Jenn Gile:** envisioning like Power Rangers or something.
[00:13:56] Paul McCarty: I almost said that and I thought, "I cannot say that word, those two words together." Um- Oh
[00:14:01] Paul McCarty: I've always been wanting to give Ken shit 'cause he's got a bunch of Power Rangers, um, helmets behind him in his, in his office. Wanna find out the story there.
Ghost Dev publishes 42 malicious gems targeting crypto developers #
**[00:14:10] Jenn Gile:** Yeah. Okay, let's talk about Ruby. Um-
**[00:14:13] Paul McCarty:** Love you, Ken. Love you, mate
[00:14:15] Jenn Gile: You discovered, well, not you, but kind of you, our automatic, uh, watchers that take a look at RubyGems flagged some concerning behavior a couple days ago.
[00:14:27] Jenn Gile: Um, 40-something, I think 42 malicious packages, uh, were published in a burst to RubyGems all from one user by the name of Ghost Dev. Very clever there.
[00:14:40] Paul McCarty: Ghost Dev. [00:14:40] Jenn Gile: Aren't I... Had to think real hard on that one. Um, and they are targeting crypto and Web3 developers through a combination of typo squatting, brandjacking, plausible utility names, um Uh, with a, essentially it's a cryptocurrency theft kit included in it.
[00:15:04] Jenn Gile: Um, I think it also has an info stealer. Remind me. I know there's a couple versions of this.
[00:15:11] Paul McCarty: Yeah. There, yeah, so it, it definitely has the w- the crypto stealer, and, um, uh, I don't know if there's like a kind of generic info stealer component. I'm looking right now. Um, I don't think there, I don't think there is.
[00:15:24] Jenn Gile: Yeah, sorry, I don't remember. It's been a couple days since I, uh- 100% ... soaked in this one. But basically, the attack flow here is, um, like what we saw with the GemStuffer campaign a month ago or so. Uh, gem install runs, uh, a file called extconf.rb, ext con. Um, and so that's a native extension build script.
[00:15:50] Jenn Gile: Kind of works in the same way as a pre-install script. Uh, it checks the environment for the little bits and bobs that it needs to run, and then I like how you said, "And then it takes a nap." So it- It takes a nap for somewhere from 20 to 40 minutes. Uh- ... presumably this is a, an evasion, you know, detection evasion technique- Evasion
[00:16:15] Jenn Gile: of like, you know, it doesn't look scary if it's asleep. And, uh, then from there it has two variants. Uh, variant one opens a reverse shell, gives the attacker remote control. That's what I was thinking of. I knew there was something else. So there's a RAT component, essentially.
[00:16:31] Paul McCarty: Yeah. [00:16:31] Jenn Gile: And then variant two is the theft kit, which, um, is posing as a tool called Wallet Guard.
[00:16:38] Jenn Gile: Uh, again, gotta love the threat actor that pretends something is a good thing, when in fact it is doing the opposite of the thing that it's telling you that it's doing.
[00:16:49] Paul McCarty: There is so much of this right now. If you download a AI skill NPM or PyPI package that ostensibly is about security, be careful.
[00:16:59] Paul McCarty: There's a pretty good chance it's the, the antithesis- It's the opposite. ... of security. It's essentially malware.
[00:17:05] Jenn Gile: Oh, womp, womp. Um- Womp, womp ... let's see. I was, like- What else is interesting to share about this one? [00:17:13] Paul McCarty: I mean, this thing had everything, right? I really, really enjoyed this. Um, one of my favorite things about it was that, you know, it was, it was Ruby, right?
[00:17:19] Paul McCarty: It was, uh, it's Ruby code. But the, um, the C2, uh, once it downloaded the second stage... So like Jenn said, there was like two versions of it. There was the reverse shell version of it, which was pretty simplistic, and then there was the other version of it that had the RAT component. Um, and RAT, it, it really wasn't a RAT.
[00:17:37] Paul McCarty: Yeah. I had a whole, I had a whole conversation back and forth with Codex about, does this qualify as a RAT? And, and Codex and I were kind of like debating each other back and forth. Well, uh... Anyhow, um, it's not really a RAT. Uh, it, we we landed on the language, Jenn. A, a backdoor. What do we say? A, a- A malicious backdoor or something like that.
[00:17:59] Paul McCarty: But, um, uh, it, uh, the code was actually in Python, so the Ruby, the second stage of the Ruby was Python. And we're seeing this a lot with- Which is
**[00:18:08] Jenn Gile:** something that we've been seeing, right? You know, the-
**[00:18:10] Paul McCarty:** 100%. We're seeing sources ... the front door, so
[00:18:12] Jenn Gile: to speak, is Ruby, and then it includes code in there that's not Ruby related.
[00:18:18] Paul McCarty: Because you have to think about these, these attack chains, and this is another thing that people do, is that they only look at what the first... They look at the NPM package and look at what it does, and they just, they don't realize that there's, like, five other stages after that that you gotta pull and deconstruct and, uh, sorry, de-obfuscate and reconstruct and whatnot.
[00:18:33] Paul McCarty: But in this case, that, that Python payload was prob- probably came from something else, right? And they're just using it- Yeah ... like a portable second stage, third stage. So, um, we're seeing-
[00:18:45] Jenn Gile: Well, let me ask- We're seeing a lot of- ... because I'm certainly not a Ruby expert, would this be one of those things that should be tipping you off that there's a problem if you download a Ruby package that's written in Python?
**[00:18:54] Jenn Gile:** Or would that be, like, a, "Could happen- I
**[00:18:58] Paul McCarty:** think- ...
**[00:18:58] Jenn Gile:** benignly"?
[00:19:01] Paul McCarty: I mean, I think there are a lot of, like NPM, like, w- a lot of NPM packages pull all kinds of other stuff, you know, so binaries and other code. I think it's a signal. I wouldn't say it's a high-quality signal. I think it's a signal you're gonna look at with other things.
[00:19:15] Paul McCarty: But in this particular case, there's a lot more high-quality signals that you saw before that in the sense that, you know, that first stage- Right ... that second stage, when it's calling out to these additional things and it's pulling files, that is a very, very clear signal. You know, YARA, even simplistic YARA rules would be able to find this stuff for you really quickly, looking for these fetches in the Axios cause and what have you, or the equivalent, sorry, the equivalent.
[00:19:37] Paul McCarty: This is Ruby, so the equivalent. Um, so you know, uh, then you combine that high-quality signal within the fact that it is in another language, you know, those things together probably
[00:19:49] Jenn Gile: signal- These, they start to add up. Well, in addition to what we've talked about, it does, uh, clipboard hijacking, so you know, of concern when a cryptocurrency address is detected on the clipboard.
[00:20:01] Jenn Gile: They exfiltrate it, and they actually replace it with a corresponding operator wallet. Um, it also is a wallet vault and secret harvesting, so reading off the, uh, ecosystems it's looking for here, uh, TronLink, MetaMask, Phantom, Binance, Coinbase, Trust Wallace wallet, uh, Exodus, Electrum. So pretty broad range of, um- Uh, crypto ecosystems that could get hit by this.
[00:20:36] Paul McCarty: Yeah, I mean, it was hitting all the big ones. Um, you know, Bitget among them, who is, uh, you know, having a hard couple of weeks. But, um, yeah, it's, it's, it's pretty typical. When we, um, when we were tracking the DPRK stuff, you know, they initially were looking at something like, I don't know, six or seven, um, uh, different companies and exchange...
[00:20:56] Paul McCarty: They were looking for the, the Chrome extensions, and there's all this kind of like infrastructure that you could tell that they were looking for this stuff. And it went from like 7 to like 16 to 28 to 35. And, you know, so they just kept looking for more and more and more and more, as more of these extensions and, and, um, you know, d- the way that people interact with their, with their crypto assets as more of those became popular, you know, DPRK and other threat actors just kept swallowing them up, swallowing them up.
**[00:21:24] Jenn Gile:** Yep.
**[00:21:24] Paul McCarty:** Yeah.
[00:21:25] Jenn Gile: Yeah, and just looking at the, uh, malicious gems here, the typosquats definitely are not sophisticated and remind me a lot of some of the other Ruby attacks we've seen over the summer. However, the brandjacking generic utility names, these resonate a little bit more as efforts to Uh, you know, name something in a smart way that somebody might actually choose on purpose rather than relying on the, you know, keyboard fat finger.
[00:21:57] Jenn Gile: You know, we've got things for Ethereum and, uh, Bitcoin and, you know, we've got a, a crypto key utils. Like there's, there's these look more legitimate, so I see a bit more maturity with the way this threat actor decided to approach this campaign. Um, something I haven't dug into yet in our data, and maybe I'll do that after we're, uh, done today, but I know it's not my imagination.
[00:22:26] Jenn Gile: I think Ruby is seeing perhaps the highest, um, velocity compared to previous months and years of malware. Uh, it does seem like attackers are starting to, not necessarily shift focus, 'cause we certainly still see it in npm, but, uh, nobody was talking about Ruby malware before the summer.
[00:22:51] Paul McCarty: Right. Yeah. And you know, I, you and I have quite the relationship now with the RubyGems people because we keep disclosing thing- I mean, like I, like I...
[00:23:02] Paul McCarty: The speed dial, "Hey guys, you got another one." Um- Mm-hmm ... but, um, you're right, and it's not like there's a corresponding drop in npm or PyPI volume. It's just now there's an increased volume in RubyGems, and we're seeing that everywhere. Same thing with VS Code and all these other places. As b- bad guys realized, I mean, part of it is what we were talking about, the portability.
[00:23:21] Paul McCarty: They're like, "Oh, shit, you know, I've got this, I've got this stager over here i- and this, this RAT, uh, in Python. I'll just load it in npm. Oh, you know what? Actually I'll do the same thing in RubyGems. Why not?" And these dependency confusion attacks, like are- Mm-hmm ... again, if we just look at it like, nobody's gonna be stupid enough to take, you know, uh, gems install, you know, Bitcoin spelled with an O and the I backwards.
[00:23:45] Paul McCarty: No. It's like, you know, you grab something, you cut and paste something from somewhere else, or it's in some automation, or the AI misspells it, or whatever. You know, a lot of it is AI. You can blame it on AI ultimately, right? Um, one thing I noticed though is that- Bright actors don't know how to use linters because like they just always leave their comments in there.
[00:24:06] Paul McCarty: And the comments are so, they're all in, always in English, or almost always in English. Occasionally you'll see Chinese comments or, you know, I've seen Vietnamese and Chinese and Thai and stuff. But other than that, they're almost always in English, and they just explicitly say, "Here's the payload right here.
**[00:24:21] Paul McCarty:** Make sure that..." You know, it's just like s- like so so
**[00:24:24] Jenn Gile:** just- The signposts are very clear.
[00:24:28] Paul McCarty: We're gonna start seeing like linters and tools coming out from people, um, uh, you know, like bad guys, right? Which I think is great because we can then, we can use those things as watering holes. But, um, but-
[00:24:41] Jenn Gile: Well, you said something that I think is worth bringing up with this particular campaign.
[00:24:45] Jenn Gile: So the previous, uh, Ruby campaign we talked about with GemStuffer, we found it in Ruby first. It turned out it also hit npm at the same time. It did. Uh, haven't necessarily seen evidence that this one made an effort to be cross ecosystem, but to your point that I don't know if you were explicitly making or not, it's possible that they've tried this previously in a different ecosystem like PyPI, perhaps had mixed results, decided to give it a go over in Ruby.
[00:25:17] Paul McCarty: Yeah, exactly. I wouldn't be surprised. Are we... I don't actually know that.
[00:25:21] Jenn Gile: No. But- That's, uh, this is a pure hypothesis here. But given- Yeah ... the behavior we've seen, wouldn't surprise me.
[00:25:28] Paul McCarty: Yeah. And, and looking the fact that they're two different languages and they're totally distinct things, right? Like it's not, it doesn't take a genius to say, you know, that PyPI stuff is probably preexisting.
[00:25:39] Paul McCarty: They probably used it over on PyPI, you know, changed it up a bit.
Slopsquatting gets more effective as AI tools hallucinate dependencies
[00:25:41] Jenn Gile: Well, and you know, I saw something- Let's see ... interesting the other day, and I can't even remember the source, so I'm sorry, maybe you will recognize this, but that there is, uh, an increase in AI tools getting confused about which ecosystem something exists in.
[00:25:57] Jenn Gile: Yeah. And this kind of relates to the slop squatting stuff. You know, there's a legitimate npm package. It makes an assumption that it's available over in Ruby. Who knows? Maybe all these package names exist legitimately in another ecosystem and this is a, an effort at slop squatting.
**[00:26:16] Paul McCarty:** Yeah, that was the podcast with Josh Bressers and, um- That's right
**[00:26:19] Paul McCarty:** the Irish guy- That was Open Source Security ... from Cloudsmith. I
**[00:26:20] Jenn Gile:** wasn't making it up.
[00:26:22] Paul McCarty: No, you were not. Um, I can't remember what I had for dinner last night, but I can remember every podcast that I've ever fricking listened to and all the content therein. Um, but yeah, I mean, I think that, um, uh- Oh my gosh, what was the, what was the point that he was trying...
[00:26:38] Paul McCarty: uh, that he was making that you brought up there? [00:26:41] Jenn Gile: I've- Oh, it was the- Either- ... the slop squatting is perhaps getting more, uh, effective as a strategy because AI tools are making- Yes ... assumptions about things existing in other ecosystems, and that's, that's a... Like, it makes total sense when you say it out loud.
[00:26:59] Jenn Gile: It's not something I've given a lot of thought to when we talk about- Yeah ... slop squatting, but, uh, I, I buy it.
[00:27:05] Paul McCarty: Yeah. In particular, he mentioned, um, he mentioned the, the, the requests, right, which is the famous Python library. Mm-hmm. Mm-hmm. Um, and the fact that you're seeing, you know, instead of Axios, you're seeing re- you know, requests over in the JavaScript world, and you're seeing Fetch.
[00:27:20] Paul McCarty: And so, basically, slop squatting absolutely is encouraging this kind of cross-ecosystem naming kind of confusion that we're seeing. Um, which is, which is very... I mean, the thing is that the people generating code now don't really know the code like they did five years ago or 10 years ago because it's, it's being vibe coded for us, right?
[00:27:42] Paul McCarty: And so because of that, a lot of this stuff is lost to the person that's actually sitting in, in front of the keyboard. Uh, the distinction there is lost on the human. Um, so the AI doesn't know. It's like, "Let me just go and look for it. Oh, hey, look, it exists. Oh, look, it looks like it does right what I want it to do.
[00:27:58] Paul McCarty: Sweet as. Happy days. Let's install it."
Wrap up #
[00:28:01] Jenn Gile: Yep. Bad times. Really good point. Bad times all around. All right. Well, I think that reaches the end of our list. Um, anything you wanna add before we wrap up? I think next week we may be recording at a different time. Uh, we'll see. You and I have to work that out with my travel schedule, but, uh-
**[00:28:19] Paul McCarty:** Uh, sure
**[00:28:20] Jenn Gile:** we'll be around the next couple of weeks, for sure.
[00:28:22] Paul McCarty: Yeah. Cool. Yeah. I mean, I'm, I'm chilling until RuCon, which I'm looking forward to in, in, um, Google RuCon in November. So I'm just chilling here and, uh, you're gonna be busy, so happy days.
[00:28:34] Jenn Gile: Well, I mean, I would love an excuse to get down to Australia. Google, if you wanna buy me a ticket, happy to-
**[00:28:40] Jenn Gile:** happy to come.
**[00:28:42] Paul McCarty:** Feel like they can probably afford it.
[00:28:44] Jenn Gile: I think they could. Um, we have a Google Workspace account, right? That seems like it should
**[00:28:49] Paul McCarty:** be- We do. I've got a bunch. True story. Okay. I got a collection.
**[00:28:54] Jenn Gile:** On that note.
**[00:28:55] Paul McCarty:** Right. On that note.
**[00:28:55] Jenn Gile:** Not looking for handouts. Thank you. Have a good one.
**[00:28:58] Paul McCarty:** See you, buddy.
**[00:28:59] Paul McCarty:** Hey, we'll take handouts. We'll take handouts.
[00:29:01] Jenn Gile: Yeah, yeah, yeah. Let's not, let's not be crazy here. We'll totally take 'em. All right. Bye.
[00:29:06] Paul McCarty: Bye, everybody. See ya.