Sep 9, 2026 · 47 min · 11 segments
Jenn and Paul also mark OpenSourceMalware's first anniversary, now tracking close to 200,000 verified threats and over 100,000 IOCs. We also discuss: - **Mini Shai-Hulud payload resurfaces on npm.**…
Jenn GileHost
Paul McCartyHost
So the one piece of news that I thought was notable over the last couple of weeks since we recorded the last time over at Aikido, Charlie published a blog about four packages that were published on September 7th, all within the same hour from the same NPM account.

The story here is not oh no these are scary something terrible is happening the story is actually that they bear the many shy hallooed uh malware from back in may uh the variant that went through aunt b and um the way that he found them is the hash matched which as you and i have talked a lot you know often The hashes are not the best way to find things, but in this case, because it stayed static, he found it that way.

Now, is this malware dangerous? No, because all the C2 infrastructure is down at this point.

But it's pretty interesting to see somebody had this stuff hanging out in their repo, presumably for, what is that, May, June, July, August, four to five months, and it's rearing its ugly head again.

The comment that he made, which I think is a great point, is this was easy to detect.

If pre-publication scanning is happening in NPM, as we've been told it is, this is like the lowest of the low-hanging fruit.

But for Paul, hey, NPM, if you are actually scanning for malware in your registry, please present evidence of said scanning because we don't see it.

Let's see, is there anything else interesting to say on this? Yeah, I mean, essentially what we think, what Charlie thinks happens is this was hanging out in somebody's pipeline.

And as we have seen with Pollenwriter and other campaigns, they accidentally pulled the malware along with it.

Well, and source code has this weird way of, you know, getting itself back into, like, old source code or isolated or orphaned source code has this weird way of working itself back into main.

So the one piece of news that I thought was notable over the last couple of weeks since we recorded the last time over at Aikido, Charlie published a blog about four packages that were published on September 7th, all within the same hour from the same NPM account.

The story here is not oh no these are scary something terrible is happening the story is actually that they bear the many shy hallooed uh malware from back in may uh the variant that went through aunt b and um the way that he found them is the hash matched which as you and i have talked a lot you know often The hashes are not the best way to find things, but in this case, because it stayed static, he found it that way.

Now, is this malware dangerous? No, because all the C2 infrastructure is down at this point.

But it's pretty interesting to see somebody had this stuff hanging out in their repo, presumably for, what is that, May, June, July, August, four to five months, and it's rearing its ugly head again.

The comment that he made, which I think is a great point, is this was easy to detect.

If pre-publication scanning is happening in NPM, as we've been told it is, this is like the lowest of the low-hanging fruit.

But for Paul, hey, NPM, if you are actually scanning for malware in your registry, please present evidence of said scanning because we don't see it.

Let's see, is there anything else interesting to say on this? Yeah, I mean, essentially what we think, what Charlie thinks happens is this was hanging out in somebody's pipeline.

And as we have seen with Pollenwriter and other campaigns, they accidentally pulled the malware along with it.

Well, and source code has this weird way of, you know, getting itself back into, like, old source code or isolated or orphaned source code has this weird way of working itself back into main.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.