<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>OpenSourceMalware Blog</title>
    <link>https://opensourcemalware.com/blog</link>
    <description>Security research and threat intelligence from OpenSourceMalware</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 23 Jun 2026 19:21:48 GMT</lastBuildDate>
    <atom:link href="https://opensourcemalware.com/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>The OpenSourceMalware Show: #9</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode09</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode09</guid>
      <description>Mastra compromise, agentjacking, and malware mythbusting</description>
      <pubDate>Thu, 18 Jun 2026 23:20:56 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>Mastra Attack Targets Crypto, Password Managers, Authenticators, and Zapier</title>
      <link>https://opensourcemalware.com/blog/mastra-npm-malware</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/mastra-npm-malware</guid>
      <description>A malicious transitive dependency hit 140+ npm packages, with tradecraft matching the Axios compromise.</description>
      <pubDate>Thu, 18 Jun 2026 17:57:35 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>The OpenSourceMalware Show #8</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode08</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode08</guid>
      <description>MSFT unpublished 73 repos, VS Code extension cooldowns, npm v12, Miasma open-sourced, and package firewalls</description>
      <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>The Pros and Cons of NPM v12&apos;s Security Improvements</title>
      <link>https://opensourcemalware.com/blog/npm-v12</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/npm-v12</guid>
      <description>NPM package manager (v12) closes serious security gaps, including making install scripts opt-in, but implementing it may not have the intended outcomes.</description>
      <pubDate>Wed, 10 Jun 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Active Malware Campaigns in January-May 2026</title>
      <link>https://opensourcemalware.com/blog/active-malware-campaigns-in-january-may-2026</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/active-malware-campaigns-in-january-may-2026</guid>
      <description>We surfaced three trends about malware: npm and PyPI growing at similar rates, ATOs aren’t the only risk, and threat actors targeted non-developers.</description>
      <pubDate>Mon, 08 Jun 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>Miasma Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds</title>
      <link>https://opensourcemalware.com/blog/miasma-blight-reaches-microsoft-73-repos-disabled-in-105-seconds</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/miasma-blight-reaches-microsoft-73-repos-disabled-in-105-seconds</guid>
      <description>A terms of use violation triggered repos for Microsoft and Azure to go down for investigations - signs point to Miasma npm malware</description>
      <pubDate>Sat, 06 Jun 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>The Software Supply Chain Malware Landscape: January - May 2026</title>
      <link>https://opensourcemalware.com/blog/the-software-supply-chain-malware-landscape-january-may-2026</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/the-software-supply-chain-malware-landscape-january-may-2026</guid>
      <description>We surfaced three trends about malware: npm and PyPI growing at similar rates, ATOs aren’t the only risk, and threat actors targeted non-developers.</description>
      <pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>The OpenSourceMalware Show #7</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode07</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode07</guid>
      <description>Miasma npm worm targets Red Hat via trusted publishing abuse, OpenSourceMalware 2026 threat data, and the gray-area Moika campaign.</description>
      <pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>The OpenSourceMalware Show #6</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode06</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode06</guid>
      <description>OSV false positives, Crowdstrike takedown of Glassworm infra, and MSFT nukes a researcher</description>
      <pubDate>Thu, 28 May 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>The OpenSourceMalware Show #5</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode05</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode05</guid>
      <description>npm staged publishing, DPRK&apos;s Axios-linked packages, TeamPCP&apos;s biggest npm maintainer compromise yet, and how a poisoned VS Code extension led to a GitHub emplo</description>
      <pubDate>Thu, 21 May 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>TeamPCP Compromises AntV and 322 Other NPM Packages</title>
      <link>https://opensourcemalware.com/blog/teampcp-compromises-antv-npm</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/teampcp-compromises-antv-npm</guid>
      <description>TeamPCP compromised npm maintainers atool and prop, republishing 324 packages including the AntV suite across 645 versions. IOCs and remediation steps inside.</description>
      <pubDate>Wed, 20 May 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Axios Attacker Behind Three More Malicious NPM Packages</title>
      <link>https://opensourcemalware.com/blog/axios-attacker-strikes-again</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/axios-attacker-strikes-again</guid>
      <description>Three malicious NPM packages connected to the March Axios compromise have been quietly harvesting developer credentials since early April</description>
      <pubDate>Tue, 19 May 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>How Malware Abuses NPM Lifecycle Scripts and VS Code Tasks</title>
      <link>https://opensourcemalware.com/blog/how-malware-abuses-npm-lifecycle-scripts-and-vs-code-tasks</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/how-malware-abuses-npm-lifecycle-scripts-and-vs-code-tasks</guid>
      <description>npm lifecycle scripts and VS Code tasks.json are productivity features that threat actors have learned to weaponize triggering malware</description>
      <pubDate>Thu, 14 May 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>The OpenSourceMalware Show #4</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode04</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode04</guid>
      <description>RubyGems bot attack, ShinyHunters ransom Canvas, and the latest on Mini Shai-Hulud.</description>
      <pubDate>Thu, 14 May 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>TeamPCP Hits TanStack, OpenSearch, and Mistral with Mini Shai-Hulud</title>
      <link>https://opensourcemalware.com/blog/teampcp-mini-shai-hulud-tanstack-opensearch-and-mistral</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/teampcp-mini-shai-hulud-tanstack-opensearch-and-mistral</guid>
      <description>TeamPCP&apos;s self-spreading npm worm &quot;Mini Shai-Hulud&quot; has compromised 170 npm packages and crossed into PyPI.</description>
      <pubDate>Wed, 13 May 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>The OpenSourceMalware Show #3</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode03</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode03</guid>
      <description>git hook persistence, Antrea compromise, Dirty Frag, cPanel exploitation, interpreted language malware</description>
      <pubDate>Thu, 07 May 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>Lazarus Group Using Git Hooks To Hide Malware</title>
      <link>https://opensourcemalware.com/blog/lazarus-group-uses-git-hooks-to-hide-malware</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/lazarus-group-uses-git-hooks-to-hide-malware</guid>
      <description>The Contagious Interview and TaskJacker campaigns now hides the stage-2 loader inside git hooks that download InvisibleFerret and Beavertail malware</description>
      <pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>CNCF Project Antrea Compromised in Daring GitHub Attack</title>
      <link>https://opensourcemalware.com/blog/cncf-project-antrea-compromised-in-daring-github-attack</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/cncf-project-antrea-compromised-in-daring-github-attack</guid>
      <description>The Antrea open-source Kubernetes project was attacked via its Jenkins integration on May 2 by an unknown threat actor who opened a malicious pull request,</description>
      <pubDate>Tue, 05 May 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>The OpenSourceMalware Show #2</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode02</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode02</guid>
      <description>Lovable and Vercel security incidents, a crazy git push RCE exploit, EDR vs AI agents, and the Mini-Shai-Hulud attack</description>
      <pubDate>Thu, 30 Apr 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>The OpenSourceMalware Show #1</title>
      <link>https://opensourcemalware.com/blog/opensourcemalware-show-episode01</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/opensourcemalware-show-episode01</guid>
      <description>TeamPCP compromises Bitwarden, npm lifecycle scripts, OWASP&apos;s npm security cheat sheet</description>
      <pubDate>Thu, 30 Apr 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>Mini Shai-Hulud Weaponizes Tasks.JSON Files</title>
      <link>https://opensourcemalware.com/blog/mini-shai-hulud-weaponizes-tasks-json-files</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/mini-shai-hulud-weaponizes-tasks-json-files</guid>
      <description>Mini Shai-Hulud is a malicious npm worm by TeamPCP. It weaponizes tasks.json files, a technique first seen in North Korean Lazarus Group campaigns.</description>
      <pubDate>Thu, 30 Apr 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Security Anti-Patterns Caused by AI Coding Tools</title>
      <link>https://opensourcemalware.com/blog/security-anti-patterns-caused-by-ai-coding-tools</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/security-anti-patterns-caused-by-ai-coding-tools</guid>
      <description>Agentic platforms like Lovable, Claude, and Codex cause unexpected security anti-patterns</description>
      <pubDate>Sun, 26 Apr 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Stardrop Supply Chain Attack Targets Venture Capital Firms, Luxury Brands, and AI Companies</title>
      <link>https://opensourcemalware.com/blog/stardrop-supply-chain-attack-targets-venture-capital-firms-luxury-brands-and-ai-companies</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/stardrop-supply-chain-attack-targets-venture-capital-firms-luxury-brands-and-ai-companies</guid>
      <description>Dozens of malicious npm packages to targeting AI companies, luxury brands, and venture capital firms. </description>
      <pubDate>Tue, 14 Apr 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>PolinRider DPRK Attack Expands Across GitHub</title>
      <link>https://opensourcemalware.com/blog/polinrider-rides-again-north-korean-attack-expands-across-github</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/polinrider-rides-again-north-korean-attack-expands-across-github</guid>
      <description>This North Korean attack has compromised 1,951 unique repositories belonging to 1,047 unique owners - a 3x growth since the campaign&apos;s discovery</description>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Velora (formerly ParaSwap) SDK Version 9.4.1 Compromised And Installing Malware</title>
      <link>https://opensourcemalware.com/blog/velora-formerly-paraswap-sdk-version-941-compromised-and-installing-malware</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/velora-formerly-paraswap-sdk-version-941-compromised-and-installing-malware</guid>
      <description>The npm package @velora-dex/sdk version 9.4.1 contains malicious code that automatically downloads and executes a shell script from a remote server  when the</description>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Hundreds of GitHub Repos Compromised By DPRK&apos;s PolinRider Campaign</title>
      <link>https://opensourcemalware.com/blog/polinrider-dprk-compromised-hundreds-of-github-repos</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/polinrider-dprk-compromised-hundreds-of-github-repos</guid>
      <description>Lazarus Group compromises GitHub repositories by implanting a malicious, obfuscated JavaScript payload.</description>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>The Social Engineering Playbook Attackers Use to Target OSS Maintainers</title>
      <link>https://opensourcemalware.com/blog/the-social-engineering-playbook-attackers-use-to-target-oss-maintainers</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/the-social-engineering-playbook-attackers-use-to-target-oss-maintainers</guid>
      <description>Account takeovers are some of the most harmful malware campaigns. Many start by compromising a maintainer account through social engineering.</description>
      <pubDate>Wed, 01 Apr 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>Has TeamPCP Pivoted To Using The PureHVNC RAT?</title>
      <link>https://opensourcemalware.com/blog/has-teampcp-pivoted-to-using-the-purehvnc-rat</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/has-teampcp-pivoted-to-using-the-purehvnc-rat</guid>
      <description>New threat campaign using PureHVNC has been tied to TeamPCP.  </description>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>TasksJacker DPRK Attack Compromises GitHub Users Via VS Code Tasks</title>
      <link>https://opensourcemalware.com/blog/tasksjacker-dprk-attack-github-vscode</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/tasksjacker-dprk-attack-github-vscode</guid>
      <description>A technical deep-dive into the next generation of DPRK attacks that borrows from Shai-hulud and Contagious Interview to compromise dozens of GitHub users</description>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Malicious Transitive Dependency in Axios Affects Millions of Users</title>
      <link>https://opensourcemalware.com/blog/axios-compromise-transitive-dependency</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/axios-compromise-transitive-dependency</guid>
      <description>The Axios NPM package has been compromised and the maintainer of the project has been locked out of their account.  This will go down in history as one of the</description>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>TeamPCP Supply Chain Campaign: A March 2026 Retrospective</title>
      <link>https://opensourcemalware.com/blog/teampcp-supply-chain-campaign-a-march-2026-retrospective</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/teampcp-supply-chain-campaign-a-march-2026-retrospective</guid>
      <description>TeamPCP executed a cascading multi-phase supply chain attack that started with a single unrevoked credential stolen from Trivy&apos;s CI pipeline.</description>
      <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
      <author>cb482791-4ef1-4762-96ad-b0ca4bdd538e</author>
    </item>
    <item>
      <title>TeamPCP Hijacks LiteLLM&apos;s PyPI Package</title>
      <link>https://opensourcemalware.com/blog/teampcp-hijacks-litellms-pypi-package-credential-stealer-hits-40k-star-project</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/teampcp-hijacks-litellms-pypi-package-credential-stealer-hits-40k-star-project</guid>
      <description>TeamPCP compromised the LiteLLM maintainer&apos;s PyPI account and published malicious versions that steal credentials from every Python process on the host.</description>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>TeamPCP Defaces Aqua Security’s Internal GitHub Org</title>
      <link>https://opensourcemalware.com/blog/teampcp-defaces-aqua-securitys-internal-github-org-44-repos-exposed</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/teampcp-defaces-aqua-securitys-internal-github-org-44-repos-exposed</guid>
      <description>TeamPCP compromised the aquasec-com GitHub organization, renaming all 44 repositories and exposing internal source code, CI/CD configs, and knowledge bases.</description>
      <pubDate>Mon, 23 Mar 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>GlassWorm Invades GitHub, NPM, VS Code, and Python</title>
      <link>https://opensourcemalware.com/blog/glassworm-invades-github-npm-open-vsx-and-vs-code</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/glassworm-invades-github-npm-open-vsx-and-vs-code</guid>
      <description>The latest Glassworm attack compromised 430+ GitHub projects by leveraging four different ecosystems</description>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Neutralinojs Compromised In DPRK Attack</title>
      <link>https://opensourcemalware.com/blog/neutralinojs-compromised-in-dprk-attack</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/neutralinojs-compromised-in-dprk-attack</guid>
      <description>DPRK threat actors compromised Neutralinojs as part of a larger attack that utilizes stolen GitHub credentials to force-push backdated malicious commits</description>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>XPACK Malware Disguises Cryptocurrency Extortion as NPM Package Monetization</title>
      <link>https://opensourcemalware.com/blog/xpack-attack-cryptocurrency-extortion-disguised-as-npm-package-monetization</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/xpack-attack-cryptocurrency-extortion-disguised-as-npm-package-monetization</guid>
      <description>A malware campaign weaponizes npm to extort crypto payments from developers during package installation</description>
      <pubDate>Mon, 09 Feb 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Malicious ClawHub Skills Use External Websites to Hide in Plain Sight</title>
      <link>https://opensourcemalware.com/blog/malicious-clawhub-skills-use-external-websites-to-hide-in-plain-sight</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/malicious-clawhub-skills-use-external-websites-to-hide-in-plain-sight</guid>
      <description>Threat actors evolved ClawHub malware by moving payloads to convincing fake websites, allowing them to completely circumvent VirusTotal scans.</description>
      <pubDate>Mon, 09 Feb 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Malicious ClawHub Skills Target OpenClaw Users</title>
      <link>https://opensourcemalware.com/blog/malicious-clawhub-skills-target-openclaw-users</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/malicious-clawhub-skills-target-openclaw-users</guid>
      <description>Malicious ClawdBot skills target ByBit, Polymarket, Axiom, Reddit and LinkedIn, installing malware on unsuspecting OpenClaw user machines.</description>
      <pubDate>Sun, 01 Feb 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>DPRK Contagious Interview “Fake Font” Abuses VS Code Tasks</title>
      <link>https://opensourcemalware.com/blog/dprk-contagious-interview-campaign-fake-font-uses-malicious-vs-code-fonts</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/dprk-contagious-interview-campaign-fake-font-uses-malicious-vs-code-fonts</guid>
      <description>“Lazarus Group&apos;s Fake Font campaign abuses VS Code task automation to silently execute BeaverTail malware, delivering the InvisibleFerret backdoor”</description>
      <pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Small Open-Source Maintainers Targeted by VS Code Tasks Malware</title>
      <link>https://opensourcemalware.com/blog/small-open-source-maintainers-targeted-by-vs-code-tasks-malware</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/small-open-source-maintainers-targeted-by-vs-code-tasks-malware</guid>
      <description>At least 21 small OSS maintainers hit in 72 hours via malicious VS Code task configurations</description>
      <pubDate>Mon, 26 Jan 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>A Comprehensive Analysis of DPRK&apos;s Contagious Interview</title>
      <link>https://opensourcemalware.com/blog/contagious-interview-gets-an-upgrade-for-2026</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/contagious-interview-gets-an-upgrade-for-2026</guid>
      <description>A single NPM package that led us to the Lazarus Groups latest campaign targeting software engineers using fake recruiters on LinkedIn, Fiverr and UpWork.</description>
      <pubDate>Tue, 20 Jan 2026 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>DPRK Malware Hiding in Microsoft VSCode Dictionary Files</title>
      <link>https://opensourcemalware.com/blog/dprk-malware-microsoft-vscode-dictionary-files</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/dprk-malware-microsoft-vscode-dictionary-files</guid>
      <description>North Korean threat actors are hiding multi-stage malware droppers in VSCode configuration files, disguised as spell-check dictionaries.</description>
      <pubDate>Tue, 23 Dec 2025 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>Elf-Stats NPM Christmas Spam Campaign</title>
      <link>https://opensourcemalware.com/blog/elf-stats-npm-christmas-spam-campaign</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/elf-stats-npm-christmas-spam-campaign</guid>
      <description>This campaign includes 36 individual packages spread across 23 different NPM users.</description>
      <pubDate>Wed, 03 Dec 2025 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>DPRK Contagious Interview Malware Weaponizes Microsoft VSCode Tasks</title>
      <link>https://opensourcemalware.com/blog/latest-contagious-interview-malware-campaign-abuses-microsoft-vscode-tasks</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/latest-contagious-interview-malware-campaign-abuses-microsoft-vscode-tasks</guid>
      <description>Lazarus Group evolves their developer-focused campaign to hide malware in VS Code tasks.json files</description>
      <pubDate>Sat, 29 Nov 2025 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
    <item>
      <title>IndonesianFoods Worm Publishes 86,000+ Malicious NPM Packages</title>
      <link>https://opensourcemalware.com/blog/indonesianfoods-worm-86000-malicious-npm-packages</link>
      <guid isPermaLink="true">https://opensourcemalware.com/blog/indonesianfoods-worm-86000-malicious-npm-packages</guid>
      <description>NPM was flooded with junk packages that waste infrastructure resources, pollute search results, and creates supply chain risks if devs accidentall consume them.</description>
      <pubDate>Thu, 13 Nov 2025 12:00:00 GMT</pubDate>
      <author>c0a15726-c5b1-4b0d-85e6-fe15553df9e2</author>
    </item>
  </channel>
</rss>