The OpenSourceMalware Show
The OpenSourceMalware Show

Hugging Face incident, AgentBaiting, RubyGems, CrashStealer, and new PolinRider research

24 July 2026 32:49 OpenSourceMalware

Listen to episode

About this episode

This week we talked about:

  • Hugging Face breach and OpenAI's rogue model claim — Hugging Face disclosed a breach with thin details; OpenAI followed up claiming one of its models caused it during an internal security test, escaping its sandbox. The security community is skeptical about OpenAI's role in this incident.
  • AgentBaiting: 6,000+ malicious GitHub repos target AI agents — Island's research found over 800 repos posing as AI skills or MCP servers, part of a wave that peaked in April. The bigger concern is malware hidden in natural-language instructions rather than code.
  • RubyGems GemStuffer copycat campaign — 2,539 new RubyGems threat reports resembling the GemStuffer campaign that used gem publishing as a channel to hide exfiltrated data.
  • RubyGems was leaking user API keys for years — A caching flaw exposed other users' API credentials under certain conditions. RubyGems fixed it fast and is notifying affected users.
  • CrashStealer: a macOS infostealer with multiple tracks — Jamf published research on this novel C/C++ infostealer impersonating Apple's crash reporter. Paul found the threat actor also running a RAT and other malware tracks in parallel.
  • Info stealers 101 — A quick primer on what characterizes an infostealer (what it targets, how it exfiltrates) and how our technology traces backward from the exfil point.
  • ChainVeil and ViteVenom are PolinRider — Jenn's research connecting Checkmarx's ChainVeil/ViteVenom npm campaign to DPRK's PolinRider via five byte-for-byte identical IOCs (wallets and XOR keys).

Episode Resources

  • (blog) Hugging Face Confirms Breach Affected Internal Datasets and Credentials, Urges Users to Take Action
  • (blog) OpenAI Says Hugging Face Was Breached by Its Pre-Release Models
  • (blog) AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware
  • (blog) GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
  • (blog) Security Advisory: Possible Leak of Legacy API Keys via Improper Cache Configuration
  • (blog) CrashStealer: C++ macOS Infostealer Posing as Crash Reporter
  • (blog) ChainVeil and ViteVenom are DPRK's PolinRider Campaign

Want to find AI jobs?

Join thousands of AI professionals finding their next opportunity

We respect your inbox. Unsubscribe at any time.

© 2026 The OpenSourceMalware Show. All rights reserved.

Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.