
DeCorey Moore
1
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
Jul 10, 2026
What Everyone Missed About The Linux Hack | Theo - t3․gg
2:21
2:31
2:42
2:49
S
0:32speaker_1ADVERTISER
I'm Eva Jovich.
T
2:14TheoHOST
So rather than just being a SoyJS dev, pretending I know what security is, I'm gonna call somebody who's a lot smarter than me, talk about the security side.

DeCorey MooreGUEST
Now, you're probably wondering, how did an open source project, a project where everyone can go and read the source code, get compromised by a malicious backdoor? That's a really good question.

DeCorey MooreGUEST
The way that it was done was actually pretty ingenious, and it was done via these two binary object files, files that were committed to the repo, not as source code, but as just blobs of data.

DeCorey MooreGUEST
These two binary files are injected into the build process, and when they're deobfuscated, turn into bash scripts.

DeCorey MooreGUEST
Now what this bash script actually ends up doing is taking these layers that hide the obfuscated data inside of good large compressed at LZMA and extracting the inner evil object file, and then making that a part of the build process so that the evil object file is now depended on by the linker at compile time.