Founder of OpenSourceMalware. Researcher, startup founder, Software Supply Chain Threat Intel

Australia
I'm monitoring DPRK-generated forks of some of the world's most popular open-source projects, including @openclaw , @FlutterDev , @TensorFlow , VS Code, @AnthropicAI, and @OpenCode. As soon as the threat actor creates a PR, @ossmalware will flag it and reach out to maintainers.
3
98
Last week, I discovered a new JavaScript stealer we are calling "WeaselBiscuit". The name is a riff on "OtterCookie", as this is a tight, stripped-down stealer. It only steals browser extension storage and clipboard contents. Includes a keylogger and dead-simple HTTP C2. No socketio C2, doesn't steal tokens/keys, etc., and no persistence. Looks like DPRK, but attribution is still a work in progress. Read more: opensourcemalware.com/blog/i…
1
1
3
87
Heya @vercel, two PRs are pending for the github.com/shadcn-ui/ui/ project, and both contain hidden DPRK malware. This is a VERY popular NPM package, and I want to make sure you kill both PRs. Here's my GitHub Issue: github.com/shadcn-ui/ui/issu…
13
19
347
36,191
I had an amazing time in France with @teamcymru_S2 and @ossmalware for the Underground Economy conference. So many great connections and looking forward to what comes next!
2
126
Ticket to @DEATHCon2026 acquired! Get yours at deathcon.io/
1
3
177
The crazy thing is, I bet that works with a bunch of the DIY scanners out there.
1
138
OMG, I called it! fetch-page-assets and html-to-gutenberg are both installing malware again. @GitHubSecurity when are you gonna realize this user is compromised by DPRK and disable his ability to publish packages? Also, aren't you supposed to be scanning packages now? Wut up with dat?!
2
3
358
Heya @npmjs and @github, maybe you should consider not letting new NPM user accounts publish hundreds of packages? Seems like an obvious control to limit the number of packages a new account can publish, but NPM has never been great at being proactive. So we get shit like this...🤦‍♀️ opensourcemalware.com/?searc…
1
1
336
TeamPCP - 0 @AusFedPolice - 2
Made with AI
1
1
6
265
The fetch-page-assets and html-to-gutenberg NPM packages have been compromised again. The maintainer was compromised by PolinRider back in May and their GitHub is absolutely overflowing with DPRK malware. Whenever the maintainer pushes new updates to his packages, the malware comes along for the ride. Nine malicious versions on @npmjs right now.
1
5
4
627
Has anyone seen #dprk using @GoDaddy for DNS registration before? I've heard a rumour that GoDaddy is accepting crypto as payment now through a third party, and I want to verify whether that's true.
1
1
163
Heya @VirginAustralia your Sydney experience is shit. First, you close Virgin only security entrance. Now today I found you have closed international to domestic transfer station. Then no priority lane at zone E checkin. Feels like Jetstar. Wtf?
1
1
205
The new WEL1DROPPER RAT is installed via approx. 800 NPM packages. The campaign is ongoing and appears to be an evolution of the Moika campaign from May. Drops Sliver via a Russian domain or Cloudflare Workers. Read more here: opensourcemalware.com/blog/r…
2
2
5
636