The OpenSourceMalware Show
Hugging Face incident, AgentBaiting, RubyGems, CrashStealer, and new PolinRider research
24 July 2026 32:49 OpenSourceMalware
Listen to episode
About this episode
This week we talked about:
- Hugging Face breach and OpenAI's rogue model claim — Hugging Face disclosed a breach with thin details; OpenAI followed up claiming one of its models caused it during an internal security test, escaping its sandbox. The security community is skeptical about OpenAI's role in this incident.
- AgentBaiting: 6,000+ malicious GitHub repos target AI agents — Island's research found over 800 repos posing as AI skills or MCP servers, part of a wave that peaked in April. The bigger concern is malware hidden in natural-language instructions rather than code.
- RubyGems GemStuffer copycat campaign — 2,539 new RubyGems threat reports resembling the GemStuffer campaign that used gem publishing as a channel to hide exfiltrated data.
- RubyGems was leaking user API keys for years — A caching flaw exposed other users' API credentials under certain conditions. RubyGems fixed it fast and is notifying affected users.
- CrashStealer: a macOS infostealer with multiple tracks — Jamf published research on this novel C/C++ infostealer impersonating Apple's crash reporter. Paul found the threat actor also running a RAT and other malware tracks in parallel.
- Info stealers 101 — A quick primer on what characterizes an infostealer (what it targets, how it exfiltrates) and how our technology traces backward from the exfil point.
- ChainVeil and ViteVenom are PolinRider — Jenn's research connecting Checkmarx's ChainVeil/ViteVenom npm campaign to DPRK's PolinRider via five byte-for-byte identical IOCs (wallets and XOR keys).
Episode Resources
- (blog) Hugging Face Confirms Breach Affected Internal Datasets and Credentials, Urges Users to Take Action
- (blog) OpenAI Says Hugging Face Was Breached by Its Pre-Release Models
- (blog) AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware
- (blog) GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
- (blog) Security Advisory: Possible Leak of Legacy API Keys via Improper Cache Configuration
- (blog) CrashStealer: C++ macOS Infostealer Posing as Crash Reporter
- (blog) ChainVeil and ViteVenom are DPRK's PolinRider Campaign
More AI podcast episodes
Browse all →Want to find AI jobs?
Join thousands of AI professionals finding their next opportunity