The OpenSourceMalware Show
Join OpenSourceMalware co-founders Jenn Gile and Paul McCarty for episode four! In this episode: * RubyGems bot attack: Hundreds of bots pushed 500-plus packages to RubyGems, some carrying exploits, forcing the registry to shut down new account signups. Jenn and Paul break down why the DDoS label may be misleading and what this exposes about the friction-vs-safety tradeoff every open source registry faces. * Canvas ransomware by ShinyHunters: ShinyHunters breached Instructure, the company behind the Canvas LMS used by over 30 million students globally, stealing 3.65TB of data including private messages between students and teachers. Instructure said almost nothing publicly for days. Jenn and Paul discuss the data sensitivity risks for minors and close with breaking news: Instructure paid the ransom. * Mini Shai Hulud and TanStack: Team PCP is not connected to the original 2025 Shai Hulud campaign. Paul explains how they used Adnan Khan's GitHub Actions cache poisoning technique to compromise TanStack and 90-plus packages without long-lived credentials, why attestation and trusted publishing didn't stop it, what the CIS country geofencing in the payload actually signals, how malware is now targeting .claude directories on developer machines, why novel malware still dominates the OpenSourceMalware database by volume, and why open sourcing their worm and doing press interviews is likely to hasten Team PCP's capture. Episode Resources: * RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded [https://thehackernews.com/2026/05/rubygems-suspends-new-signups-after.html] * RubyGems status page [https://status.rubygems.org/incidents/cytf062tkwtt] * OpenSourceMalware RubyGems threat records [https://opensourcemalware.com/?type=package&ecosystem=rubygems] * OpenSourceMalware Mini Shai-Hulud threat records [https://opensourcemalware.com/?search=%23mini-shai-hulud] * Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak [https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html] * blog: Mini Shai-Hulud Borrowed Its Best Trick From PolinRider [https://opensourcemalware.com/blog/mini-shai-hulud] * blog: TeamPCP Compromises MistralAI and OpenSearch [https://opensourcemalware.com/blog/teampcp-mistralai-opensearch-compromised] * TanStack npm supply-chain compromise postmortem [https://tanstack.com/blog/npm-supply-chain-compromise-postmortem] * The Monsters in Your Build Cache - GitHub Actions Cache Poisoning [https://adnanthekhan.com/2024/05/06/the-monsters-in-your-build-cache-github-actions-cache-poisoning/] * TeamPCP interview [https://buymeacoffee.com/insidedarknet/teampcp-interview]
5 Episoder
Kommentarer
0Vær den første til å kommentere
Registrer deg nå og bli medlem av The OpenSourceMalware Show sitt community!