The Matthew Chapman Podcast

Shai-Hulud Worm Returns, Booby-Trapping Claude Code and VS Code

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:53
Here is your briefing for Thursday, October eighth, twenty twenty-six. The Shai-Hulud worm is back, and this time it came in through an A.I. infrastructure package. Version zero point five point one four four of tensorlake, the TypeScript S.D.K. for Tensorlake's sandboxes and cloud services, shipped with a preinstall hook that launches an obfuscated, Bun-based credential stealer. StepSecurity says the malicious files were pushed to the project's main branch under a maintainer's name, and the repo's own release workflow published them to npm. Once it runs, it harvests secrets from local files, C.I., Kubernetes, and Vault, then republishes every package the victim can publish, complete with Sigstore provenance. It also writes dot claude settings and dot vscode tasks files into any repo it can reach, so it runs again the next time someone opens the project in Claude Code or VS Code. And if you revoke the stolen GitHub token, a watchdog may fire a destructive payload. So, pull the bad version, rotate everything, and clean the box before you kill the token. SonicWall pushed hotfixes for four flaws in its S.M.A. one thousand remote access appliances. The headliner is a server-side request forgery in the WorkPlace login portal, rated ten out of ten, that needs no login and lets an attacker reach internal functions and perform unauthorized operations. It was found by Benoît Sevens of Anthropic, and SonicWall says there's no sign of exploitation yet. Here's the uncomfortable part. This is the third pre-auth, ten-point-oh S.S.R.F. in WorkPlace this year, and the July and September pairs were both exploited. The September fix versions are affected too, so patching last month doesn't get you off the hook. There's no workaround, and the appliance reboots after the install. Schedule the window today, before somebody chains it the way they did in July. J.Frog disclosed a critical bug in LMCache, the open source cache that speeds up L.L.M. servers like v.L.L.M. In multiprocess mode, the cache server takes messages over an unauthenticated ZeroMQ socket and unpacks one type with Python's pickle, before checking anything. One crafted message runs the sender's code, and on the official container images, that code runs as root. There is no fixed version. The good news is that the server listens on localhost by default. The bad news is that LMCache's own example Kubernetes deployment binds it to every interface. If you're sharing a cache across nodes, keep that port on a trusted cluster network and nowhere else. Pickle on an open socket, in twenty twenty-six... some lessons just refuse to stick. Brian Krebs reports that the teenager in Amman, Jordan, suspected of leading ShinyHunters, known as Rey, was detained while the group was extorting Jeppesen ForeFlight, the navigation and digital aviation unit Boeing sold to Thoma Bravo last year. Boeing confirmed the extortion attempt. Sources say the stolen data could pose operational safety and security risks, which gave the F.B.I. case new urgency. The group's way in was an Oracle PeopleSoft zero-day it began exploiting in June. When Mandiant shipped web application firewall rules for people who couldn't patch, ShinyHunters got around them with an old U.R.L. encoding trick. That's how they reached an F.B.I. recruiting site exposing more than five thousand personnel. A firewall rule buys you time. It's not a patch. The Justice Department charged Zohar Pinhasi, owner of the Florida firm MonsterCloud, with wire fraud. Prosecutors say he told ransomware victims not to pay, sold them on proprietary decryption tools, and then quietly paid the attackers for the decryptor himself. The markup was the business model. In one case he allegedly paid about eight thousand two hundred dollars in ransom and billed the client about one hundred fifty thousand. In total, prosecutors say he charged clients more than nineteen million dollars while paying more than eight million in ransoms. If your incident response vendor promises magic decryption, ask exactly how it works, and get it in writing. A worm that publishes itself with valid provenance, a login portal that keeps getting the same bug, a cache server that trusts every message, a firewall rule beaten by U.R.L. encoding, and a recovery firm that was paying the attackers all along. The common thread is trust that nobody bothered to check. That's your brief. Stay sharp, patch your systems, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show