Skip to main content
DeCorey Moore

DeCorey Moore

Jul 10, 2026

speaker_1ADVERTISER
0:32
I'm Eva Jovich.
0:33
I'm DeCorey Moore.
0:33
Want to train like a Red Bull athlete?
TheoHOST
2:14
So rather than just being a SoyJS dev, pretending I know what security is, I'm gonna call somebody who's a lot smarter than me, talk about the security side.
2:21
Now, you're probably wondering, how did an open source project, a project where everyone can go and read the source code, get compromised by a malicious backdoor? That's a really good question.
2:31
The way that it was done was actually pretty ingenious, and it was done via these two binary object files, files that were committed to the repo, not as source code, but as just blobs of data.
2:42
These two binary files are injected into the build process, and when they're deobfuscated, turn into bash scripts.
2:49
Now what this bash script actually ends up doing is taking these layers that hide the obfuscated data inside of good large compressed at LZMA and extracting the inner evil object file, and then making that a part of the build process so that the evil object file is now depended on by the linker at compile time.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.