Podcast

The OpenSourceMalware Show

When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that…

Download on the App Store

Already have it? Open in the app

Latest episodes

  1. Popular Rust package compromise, multi-ecosystem typosquatting attack, trends in binary payloads20 Aug 2026
  2. Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft13 Aug 2026
  3. New npm worm, WEL1DROPPER AI slopsquatting campaign, DPRK NullRider innovation7 Aug 2026
  4. Hugging Face update, GitHub security improvements, DPRK linked to chald/debug, and more new PolinRider research30 Jul 2026
  5. Hugging Face incident, AgentBaiting, RubyGems, CrashStealer, and new PolinRider research24 Jul 2026
  6. Dependabot cooldowns, Jscrambler and AsynchAPI compromises, new PolinRider research16 Jul 2026
  7. Open VSX security improvements, new PolinRider researcher, shady vendor practices9 Jul 2026
  8. GitHub security improvements, shady vendor practices2 Jul 2026
  9. How malicious OSS is evolving in 2026, feat. DPRK innovations25 Jun 2026
  10. Mastra compromise, agentjacking research, busting malware myths18 Jun 2026