
The OpenSourceMalware Show
Subscribe in ParasocialFree on the App Store for iPhone, iPad and Mac. Once it is installed, tap this link again and the show is yours. Already have it? Open in Parasocial.
About
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are happening every day.Hosted by Jenn Gile and Paul McCarty (co-founders of OpenSourceMalware), this podcast explores the latest trends and attacks, and helps defenders understand the tactics needed to prevent their orgs from being the next target.OpenSourceMalware provides community-driven...
Also on
Recent episodes
- Live from Strasbourg & Underground Economy
- TeamPCP members arrested, PolinRider persistence mechanisms defeat remediation attempts
- Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads
- Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft
- New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation
- Hugging Face update, GitHub security improvements, DPRK linked to chald/debug, and more new PolinRider research
- Hugging Face incident, AgentBaiting, RubyGems, CrashStealer, and new PolinRider research
- Dependabot cooldowns, Jscrambler and AsynchAPI compromises, new PolinRider research
- Open VSX security improvements, new PolinRider researcher, shady vendor practices
- GitHub security improvements, shady vendor practices