w/ Jenn Gile & Paul McCarty, Open Source Malware
In this episode of The Secure Disclosure, Jenn Gile and Paul McCarty from Open Source Malware break down how malicious packages are evolving, why developers are now a primary target, and what security teams still get wrong about software supply chain defense. From contagious interview campaigns to registry weaknesses and response playbooks, this conversation covers the real world risks behind today’s open source malware problem. Sponsored by Aikido Security https://aikido.dev Learn more about Open Source Malware https://opensourcemalware.com/ Connect with Jenn Gile https://www.linkedin.com/in/jenngile/ Connect with Paul McCarty https://www.linkedin.com/in/mccartypaul/ Follow The Secure Disclosure on LinkedIn https://www.linkedin.com/company/the-secure-disclosure Chapters 00:00:00 Open Source Malware Cold Open 00:00:29 Meet Jenn Gile and Paul McCarty 00:01:04 Why They Built Open Source Malware 00:06:51 Why Developers Are Now the Primary Target 00:10:34 How the Contagious Interview Campaign Works 00:15:54 What the Industry Needs to Do Next 00:20:50 Why Malicious Packages Keep Increasing 00:31:10 Would You Rather
Tell us who, why, and how to reach them. We read every submission.