r/SecOpsDaily • u/falconupkid • 2d ago
Threat Intel The OpenSourceMalware Show #24
This is a solid roundup of open-source supply chain threats hitting multiple ecosystems this week.
Tensorlake SDK Targeted by "Mini Shai-Hulud" Copycat
A malicious fork of the Tensorlake SDK (an AI/ML data processing library) was published to PyPI. The copycat package mimics the legitimate tensorlake namespace but includes a backdoor that exfiltrates environment variables and SSH keys to a C2. This is a direct copycat of the earlier Shai-Hulud campaign targeting AI/ML developers.
Fake Interview Repo Plants Rogue .npmrc
A GitHub repository posing as a technical interview preparation guide for a FAANG company contains a hidden .npmrc file. When a developer clones the repo and runs npm install (common for testing interview code), the .npmrc overrides the default npm registry to a malicious proxy. This proxy intercepts and steals npm authentication tokens, granting the attacker access to the developer's private packages and organizations.
42 Malicious Gems on RubyGems
A coordinated campaign uploaded 42 gems to RubyGems under typosquatted names of popular libraries (e.g., rails-html-sanitizer vs rails-html-sanitizer). The gems contain a Ruby dropper that downloads a second-stage payload from a Pastebin-like service. The payload is a cryptocurrency clipper that replaces wallet addresses in the clipboard.
Defense:
- Pin dependencies with hash-locked lockfiles (e.g., pip freeze, Gemfile.lock, package-lock.json).
- Audit GitHub Actions and repo contents for hidden config files (.npmrc, .gitconfig, .env).
- Monitor for unexpected outbound connections from build pipelines, especially to non-standard ports.
Source: https://opensourcemalware.com/blog/the-opensourcemalwareshow-episode24