惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
A
About on SuperTechFans
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
Netflix TechBlog - Medium
Microsoft Security Blog
Microsoft Security Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
博客园 - Franky
D
Docker
Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
Last Week in AI
Last Week in AI
U
Unit 42
F
Fortinet All Blogs
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
P
Proofpoint News Feed
月光博客
月光博客
G
Google Developers Blog

Risky Business Features

Who gets to hack the hackers? How Brian Krebs doxxed TeamPCP James Kettle on inventing new attack techniques with LLMs How private LLM inference actually works Benchmarks, borders and the true cost of AI regulation Fortibleed: The bleeding edge of AI cybercrime What to do 'til the bugpocalypse gets here Mythos on your desk? Using local LLMs for code reviews Pitching security startups to VCs in the AI era How using open weight models can blow up in your face The state of the art in AI model jailbreaks Why NPM v12 won’t stop supply chain attacks Everything is getting much worse, much faster Solo podcast: A deep dive on TeamPCP How to survive supply chain attacks How the CopyFail disclosure went sideways NCSC’s Ollie Whitehouse on surviving the "bugpocalypse" What a great agentic AI deployment plan looks like Mythos smythos! How to find 0day with lesser models Solving the AI agent identity problem A deep dive on AI model distillation attacks Feature Interview: Nicholas Carlini, Anthropic A builder's perspective on Mythos and frontier models Mythos and 0day: Fixing exploits is not safety Mythos and 0day: A hacker’s perspective What happens after North Korea infiltrates? Why CISOs need to be more flexible in the AI era A Risky Biz Experiment: Hunting for iOS 0day with AI Interview: Former NSA and CIA cyber leaders on offensive AI When disaster strykes - Risky Business Media
Hunting software supply chain malware
James Wilson · 2026-09-11 · via Risky Business Features

Risky Business Features Podcast

September 11, 2026

Presented by

James Wilson

James Wilson

Technology Editor

In this podcast episode, OpenSourceMalware founder Paul McCarty joins James Wilson to explain how researchers find and analyse malicious packages, GitHub repositories and developer tools.

Paul walks James through static analysis, deobfuscation and reconstructing multi-stage kill chains to identify what attackers are trying to steal. They also discuss how LLMs make malware development easier while introducing operational security mistakes.

The pair examine DPRK tradecraft, blockchain-based payload delivery and what Paul calls Pollen Rider, which can reinfect developers through their own repositories.

Your browser does not support the audio element.

Hunting software supply chain malware

0:00 / 75:04

Logo