
Episode #17
Hacker Summer Camp trends, npm kills 2FA-bypass tokens, DPRK tradecraft
This week we talked about: Hacker Summer Camp trends. Jenn and Paul share observations from Black Hat, DEF CON, and BSides Las Vegas last week, including a maturing AI security conversation that has shifted to focus on where AI still falls short, particularly the last mile of precision and finesse that still requires a human to verify. They also discuss the emerging challenge of identifying malicious AI skills, where the natural language format makes static analysis much harder than it is for traditional package ecosystems. And they revisit the recurring gap between security teams who understand binary malware and incident response and those who understand the open source software supply chain. GitHub revokes npm bypass-2FA token privileges. GitHub announced it is closing a gap that let npm granular access tokens configured to bypass two factor authentication perform sensitive account, org, and package management actions, a change Jenn and Paul say is overdue but underexplained. DPRK's NullReceiver technique keeps spreading. Following up on last week's episode, Paul shares that the number of packages using the NullReceiver technique, tied to the PolinRider campaign, has grown well past the seven originally confirmed, and that DPRK's use of crypto payments for infrastructure like VPN services could offer new tracking opportunities for defenders. Episode resources: (blog) Restricting npm bypass-2FA granular access tokens (blog) NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding






