D2DO300: Open Source Malware!

The Everything Feed - All Packet Pushers Pods41mApril 15, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “D2DO300: Open Source Malware!” inside PodZeus.

AI-Generated Summary

In this episode of Day 2 DevOps, hosts Ned Bellavance and Kyler Middleton dive deep into the rising threat of open source malware, particularly within NPM and AI agent ecosystems. Guest Jen Geil, co-founder of Open Source Malware, reveals how malicious actors are exploiting the open source supply chain through account takeovers, transitive dependencies, and AI-driven infiltration. She highlights a major 2025 incident involving the NX package, where attackers used post-install scripts to weaponize AI tools like Cloud and Gemini, tricking them into scraping developer secrets and exposing 3,000 repositories. The episode underscores how AI's ease of use and high permission levels have created new attack vectors, with malicious agents now infiltrating marketplaces like OpenClaw. Despite the alarming pace of innovation in cyberattacks—such as using invisible Unicode characters to hide malicious code—Geil emphasizes that the situation is not hopeless. She introduces the Open Source Malware database, a community-driven, publicly accessible threat intelligence platform designed to track and expose malicious packages, domains, and AI skills. The episode concludes with actionable advice for developers and organizations: implement dependency pinning, cool-down policies, and cross-functional security teams, while advocating for systemic changes in platform design and continuous education across all departments, not just engineering. The episode delivers a sobering yet hopeful message: while the speed of AI and open source development has outpaced traditional security measures, collective vigilance, community-driven tools, and proactive defense strategies can still make a difference. The key takeaways include slowing down the adoption of new packages, adopting automated scanning tools integrated with the Open Source Malware API, and expanding security training beyond software engineers to include finance, marketing, and sales teams. The hosts and guest stress that the responsibility isn't just on individuals but requires organizational commitment and structural changes in how open source ecosystems are governed.

Key Takeaways
1

Malware in open source packages, especially NPM, has surged—over 90% of open source malware is now found in NPM packages, with a sharp increase since mid-2025.

2

Attackers are increasingly using AI tools as attack vectors by tricking locally installed AI agents (like Cloud, Gemini, Amazon Q) into scraping secrets via malicious post-install scripts.

3

Implementing a 'cool-down policy'—delaying package updates for 24–72 hours—can prevent rapid exploitation of newly published malicious packages.

4

The Open Source Malware database (opensourcemalware.com) is a free, community-driven threat intelligence platform offering real-time detection of malicious packages, domains, and AI skills.

5

Invisible Unicode characters and deceptive documentation in VS Code extensions and AI skills are now being used to hide malicious code, making manual review insufficient.

…and 3 more takeaways available in PodZeus

Chapters
0:00
3 min

The Rise of Machine-First Malware

They are creating malware in ways that are more designed to trick machines rather than trick humans.

Highlight
2:30
5 min

NPM: The Epicenter of Open Source Malware

NPM is the source of over 90% of open source malware.

Highlight
7:30
8 min

The NX Attack: AI as a Rogue Agent

They got these AIs to be helpful. And once they flipped over, they started scraping the developer machines for secrets.

Highlight
15:00
8 min

AI Agent Marketplaces: The New Attack Frontier

The rise of AI agent marketplaces like OpenClaw has led to hundreds of malicious agents being published. These agents operate with full user permissions, effectively giving attackers admin access to personal and corporate accounts.

22:30
8 min

Defensive Strategies for Developers

Practical advice for developers: pin dependencies, implement cool-down policies, and use sandboxing. The episode stresses that slowing down adoption can block many malware campaigns.

High-Impact Quotes
NPM is the source of over 90% of open source malware.
Jen Geil3:52
Viral: 90.0
They got these AIs to be helpful. And once they flipped over, they started scraping the developer machines for secrets.
Jen Geil11:46
Viral: 88.0
This is not something that is hopeless.
Jen Geil39:21
Viral: 87.0
Speakers

Hosts

Ned BellavanceKyler Middleton

Guest

Jen Geil
Topics Discussed
open source malware95%npm security90%ai agent security88%supply chain attacks85%threat intelligence80%developer security78%dependency management75%invisible code obfuscation70%
People & Brands

Jen Geil

person

25xPositive

NPM

other

22xNegative

Open Source Malware

organization

18xPositive

Paul McCurry

person

8xPositive

NX

other

6xNegative

OpenClaw

other

4xNegative

VS Code

other

4xNeutral

OSV

other

3xNeutral

GitHub Actions

other

3xNeutral

Endor Labs

organization

3xNeutral

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “D2DO300: Open Source Malware!” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime