56,966 blogs · [ { "id": "01a0e263-ec49-7313-85e7-3db12a2b1b19", "title": "PolinRider is A/B Testing its Way Past Your Detections", "url": "https://opensourcemalware.com/blog/polinrider-is-a-b-testing-its-way-past-your-detections", "published_at": "2026-09-26T08:06:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12abbb94d", "title": "The OpenSourceMalware Show #22", "url": "https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode22", "published_at": "2026-09-25T05:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12b2cb6cd", "title": "WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials", "url": "https://opensourcemalware.com/blog/introducing-weaselbiscuit", "published_at": "2026-09-17T08:08:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12b6e9f85", "title": "The OpenSourceMalware Show #21", "url": "https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode21", "published_at": "2026-09-17T06:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12c424aa5", "title": "The OpenSourceMalware Show #20", "url": "https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode20", "published_at": "2026-09-09T21:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12c9a517f", "title": "The OpenSourceMalware Show #19", "url": "https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode19", "published_at": "2026-08-28T06:02:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12cb2ce9c", "title": "NPM Isn't Prepared For North Korean PolinRider Attack", "url": "https://opensourcemalware.com/blog/polinrider-npm-case-study-dprk-attack", "published_at": "2026-08-25T00:23:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12d6fc1a9", "title": "The OpenSourceMalware Show #18", "url": "https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode18", "published_at": "2026-08-21T06:03:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12dc7f737", "title": "Windows Infostealer Hits npm and Ruby", "url": "https://opensourcemalware.com/blog/windows-infostealer-stubmaker-npm-ruby", "published_at": "2026-08-19T09:29:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12e3576c3", "title": "StubMaker RubyGems Campaign Delivers a Windows Infostealer", "url": "https://opensourcemalware.com/blog/stubmaker-rubygems-windows-infostealer", "published_at": "2026-08-16T22:16:30+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12e49e71e", "title": "The OpenSourceMalware Show #17", "url": "https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode17", "published_at": "2026-08-14T06:38:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12e98746a", "title": "A Developer's Guide to Getting Rid of PolinRider", "url": "https://opensourcemalware.com/blog/developer-guide-getting-over-polinrider", "published_at": "2026-08-13T21:13:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db12f66559a", "title": "The OpenSourceMalware Show #16", "url": "https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode16", "published_at": "2026-08-08T01:56:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db1300e4315", "title": "Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages", "url": "https://opensourcemalware.com/blog/russian-ai-slopsquatting-npm-campaign", "published_at": "2026-08-06T23:26:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13044beac", "title": "New npm Worm Hits 400+ Packages Including Keyv, Cachable", "url": "https://opensourcemalware.com/blog/new-npm-worm-keyv-cachable", "published_at": "2026-08-05T00:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db130b509c3", "title": "NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding", "url": "https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique", "published_at": "2026-08-02T01:05:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13140073a", "title": "The OpenSourceMalware Show #15", "url": "https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode15", "published_at": "2026-07-31T06:07:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db131c9ec89", "title": "PolinRider Caused Dozens of npm, Go, PHP Compromises", "url": "https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-go-compromises", "published_at": "2026-07-31T01:56:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db132a834b0", "title": "NPM Implements Pre-Publication Malware Scanning, But Will It Work?", "url": "https://opensourcemalware.com/blog/npm-prepublication-malware-scanning", "published_at": "2026-07-31T00:15:58+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13359d46c", "title": "The OpenSourceMalware Show #14", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode14", "published_at": "2026-07-23T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db133c2bd44", "title": "ChainVeil and ViteVenom are DPRK’s PolinRider Campaign", "url": "https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign", "published_at": "2026-07-17T23:29:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db1346a85c0", "title": "The OpenSourceMalware Show #13", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode13", "published_at": "2026-07-16T22:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db134fe952e", "title": "PolinRider Confirmed Footprint Grows 6.5x Since March", "url": "https://opensourcemalware.com/blog/polinrider-blast-radius-grows", "published_at": "2026-07-15T19:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db135184590", "title": "Cybersecurity Startup Publishes Infostealers to NPM", "url": "https://opensourcemalware.com/blog/cybersecurity-startup-publishes-infostealers-to-npm", "published_at": "2026-07-09T23:53:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13528a58d", "title": "The OpenSourceMalware Show #12", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode12", "published_at": "2026-07-09T23:52:35+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db1354b160a", "title": "PolinRider Jumps the Fence to Go, Packagist, npm, PyPI", "url": "https://opensourcemalware.com/blog/polinrider-jumps-the-fence", "published_at": "2026-07-08T16:52:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db135e8fd27", "title": "The OpenSourceMalware Show #11", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode11", "published_at": "2026-07-02T23:30:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db1364aabef", "title": "The OpenSourceMalware Show #10", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode10", "published_at": "2026-06-25T22:30:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db1367c72cc", "title": "The OpenSourceMalware Show #9", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode09", "published_at": "2026-06-18T23:20:56+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db1368216ae", "title": "Mastra Attack Targets Crypto, Password Managers, Authenticators, and Zapier", "url": "https://opensourcemalware.com/blog/mastra-npm-malware", "published_at": "2026-06-18T05:57:35+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db136efc9eb", "title": "The OpenSourceMalware Show #8", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode08", "published_at": "2026-06-11T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13721159d", "title": "The Pros and Cons of NPM v12's Security Improvements", "url": "https://opensourcemalware.com/blog/npm-v12", "published_at": "2026-06-10T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13743a882", "title": "Active Malware Campaigns in January-May 2026", "url": "https://opensourcemalware.com/blog/active-malware-campaigns-in-january-may-2026", "published_at": "2026-06-08T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db137f6a567", "title": "Miasma Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds", "url": "https://opensourcemalware.com/blog/miasma-blight-reaches-microsoft-73-repos-disabled-in-105-seconds", "published_at": "2026-06-06T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13876da0c", "title": "The Software Supply Chain Malware Landscape: January - May 2026", "url": "https://opensourcemalware.com/blog/the-software-supply-chain-malware-landscape-january-may-2026", "published_at": "2026-06-03T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db138ffcc3b", "title": "The OpenSourceMalware Show #7", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode07", "published_at": "2026-06-03T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db139cb4abb", "title": "The OpenSourceMalware Show #6", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode06", "published_at": "2026-05-28T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13a0f8bc1", "title": "The OpenSourceMalware Show #5", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode05", "published_at": "2026-05-21T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13a372de5", "title": "TeamPCP Compromises AntV and 322 Other NPM Packages", "url": "https://opensourcemalware.com/blog/teampcp-compromises-antv-npm", "published_at": "2026-05-20T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13a3e142f", "title": "Axios Attacker Behind Three More Malicious NPM Packages", "url": "https://opensourcemalware.com/blog/axios-attacker-strikes-again", "published_at": "2026-05-19T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13af25fa3", "title": "How Malware Abuses NPM Lifecycle Scripts and VS Code Tasks", "url": "https://opensourcemalware.com/blog/how-malware-abuses-npm-lifecycle-scripts-and-vs-code-tasks", "published_at": "2026-05-14T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13baa5d86", "title": "The OpenSourceMalware Show #4", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode04", "published_at": "2026-05-14T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13c40034c", "title": "TeamPCP Hits TanStack, OpenSearch, and Mistral with Mini Shai-Hulud", "url": "https://opensourcemalware.com/blog/teampcp-mini-shai-hulud-tanstack-opensearch-and-mistral", "published_at": "2026-05-13T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13c791123", "title": "The OpenSourceMalware Show #3", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode03", "published_at": "2026-05-07T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13d579f90", "title": "Lazarus Group Using Git Hooks To Hide Malware", "url": "https://opensourcemalware.com/blog/lazarus-group-uses-git-hooks-to-hide-malware", "published_at": "2026-05-06T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13ddc76ac", "title": "CNCF Project Antrea Compromised in Daring GitHub Attack", "url": "https://opensourcemalware.com/blog/cncf-project-antrea-compromised-in-daring-github-attack", "published_at": "2026-05-05T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13ed0925e", "title": "The OpenSourceMalware Show #2", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode02", "published_at": "2026-04-30T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db13fc6d5dd", "title": "The OpenSourceMalware Show #1", "url": "https://opensourcemalware.com/blog/opensourcemalware-show-episode01", "published_at": "2026-04-30T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db1403cc1ec", "title": "Mini Shai-Hulud Weaponizes Tasks.JSON Files", "url": "https://opensourcemalware.com/blog/mini-shai-hulud-weaponizes-tasks-json-files", "published_at": "2026-04-30T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db14064b65c", "title": "Security Anti-Patterns Caused by AI Coding Tools", "url": "https://opensourcemalware.com/blog/security-anti-patterns-caused-by-ai-coding-tools", "published_at": "2026-04-26T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db140e7a26b", "title": "Stardrop Supply Chain Attack Targets Venture Capital Firms, Luxury Brands, and AI Companies", "url": "https://opensourcemalware.com/blog/stardrop-supply-chain-attack-targets-venture-capital-firms-luxury-brands-and-ai-companies", "published_at": "2026-04-14T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db141ad2c44", "title": "PolinRider DPRK Attack Expands Across GitHub", "url": "https://opensourcemalware.com/blog/polinrider-rides-again-north-korean-attack-expands-across-github", "published_at": "2026-04-12T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db142a697de", "title": "Velora (formerly ParaSwap) SDK Version 9.4.1 Compromised And Installing Malware", "url": "https://opensourcemalware.com/blog/velora-formerly-paraswap-sdk-version-941-compromised-and-installing-malware", "published_at": "2026-04-08T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db1436cf75e", "title": "The Social Engineering Playbook Attackers Use to Target OSS Maintainers", "url": "https://opensourcemalware.com/blog/the-social-engineering-playbook-attackers-use-to-target-oss-maintainers", "published_at": "2026-04-01T12:00:00+00:00" }, { "id": "01a0e263-ec49-7313-85e7-3db14392399d", "title": "Has TeamPCP Pivoted To Using The PureHVNC RAT?", "url": "https://opensourcemalware.com/blog/has-teampcp-pivoted-to-using-the-purehvnc-rat", "published_at": "2026-03-31T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cacb933815", "title": "TasksJacker DPRK Attack Compromises GitHub Users Via VS Code Tasks", "url": "https://opensourcemalware.com/blog/tasksjacker-dprk-attack-github-vscode", "published_at": "2026-03-31T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cacc0f5e48", "title": "Malicious Transitive Dependency in Axios Affects Millions of Users", "url": "https://opensourcemalware.com/blog/axios-compromise-transitive-dependency", "published_at": "2026-03-31T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03caccbaaafa", "title": "TeamPCP Supply Chain Campaign: A March 2026 Retrospective", "url": "https://opensourcemalware.com/blog/teampcp-supply-chain-campaign-a-march-2026-retrospective", "published_at": "2026-03-26T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03caccf1f7c9", "title": "TeamPCP Hijacks LiteLLM's PyPI Package", "url": "https://opensourcemalware.com/blog/teampcp-hijacks-litellms-pypi-package-credential-stealer-hits-40k-star-project", "published_at": "2026-03-25T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cacd49a40c", "title": "TeamPCP Defaces Aqua Security’s Internal GitHub Org", "url": "https://opensourcemalware.com/blog/teampcp-defaces-aqua-securitys-internal-github-org-44-repos-exposed", "published_at": "2026-03-23T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cacd834271", "title": "GlassWorm Invades GitHub, NPM, VS Code, and Python", "url": "https://opensourcemalware.com/blog/glassworm-invades-github-npm-open-vsx-and-vs-code", "published_at": "2026-03-16T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cace4609bb", "title": "Hundreds of GitHub Repos Compromised By DPRK's PolinRider Campaign", "url": "https://opensourcemalware.com/blog/polinrider-dprk-compromised-hundreds-of-github-repos", "published_at": "2026-03-08T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cacec20d08", "title": "Neutralinojs Compromised In DPRK Attack", "url": "https://opensourcemalware.com/blog/neutralinojs-compromised-in-dprk-attack", "published_at": "2026-03-06T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cacf1678b5", "title": "XPACK Malware Disguises Cryptocurrency Extortion as NPM Package Monetization", "url": "https://opensourcemalware.com/blog/xpack-attack-cryptocurrency-extortion-disguised-as-npm-package-monetization", "published_at": "2026-02-09T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cacfc4cf95", "title": "Malicious ClawHub Skills Use External Websites to Hide in Plain Sight", "url": "https://opensourcemalware.com/blog/malicious-clawhub-skills-use-external-websites-to-hide-in-plain-sight", "published_at": "2026-02-09T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cad06bcf1d", "title": "Malicious ClawHub Skills Target OpenClaw Users", "url": "https://opensourcemalware.com/blog/malicious-clawhub-skills-target-openclaw-users", "published_at": "2026-02-01T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cad0eae8a4", "title": "DPRK Contagious Interview “Fake Font” Abuses VS Code Tasks", "url": "https://opensourcemalware.com/blog/dprk-contagious-interview-campaign-fake-font-uses-malicious-vs-code-fonts", "published_at": "2026-01-28T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cad1918c8f", "title": "Small Open-Source Maintainers Targeted by VS Code Tasks Malware", "url": "https://opensourcemalware.com/blog/small-open-source-maintainers-targeted-by-vs-code-tasks-malware", "published_at": "2026-01-26T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cad25d4567", "title": "A Comprehensive Analysis of DPRK's Contagious Interview", "url": "https://opensourcemalware.com/blog/contagious-interview-gets-an-upgrade-for-2026", "published_at": "2026-01-20T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cad2dfa7b8", "title": "DPRK Malware Hiding in Microsoft VSCode Dictionary Files", "url": "https://opensourcemalware.com/blog/dprk-malware-microsoft-vscode-dictionary-files", "published_at": "2025-12-23T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cad3495fc1", "title": "Elf-Stats NPM Christmas Spam Campaign", "url": "https://opensourcemalware.com/blog/elf-stats-npm-christmas-spam-campaign", "published_at": "2025-12-03T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cad354d9c9", "title": "DPRK Contagious Interview Malware Weaponizes Microsoft VSCode Tasks", "url": "https://opensourcemalware.com/blog/latest-contagious-interview-malware-campaign-abuses-microsoft-vscode-tasks", "published_at": "2025-11-29T12:00:00+00:00" }, { "id": "01a0e263-ec4a-7020-b2a6-03cad3f9330b", "title": "IndonesianFoods Worm Publishes 86,000+ Malicious NPM Packages", "url": "https://opensourcemalware.com/blog/indonesianfoods-worm-86000-malicious-npm-packages", "published_at": "2025-11-13T12:00:00+00:00" } ] posts Claim your blog
Back to opensourcemalware.com
Blog · corpus.blog/blogs/opensourcemalware.com/posts

opensourcemalware.com

opensourcemalware.com

2026

2025