More Open Source Security episodes

Open Source Malware with Paul McCarty thumbnail

Open Source Malware with Paul McCarty

Published 13 Apr 2026

Duration: 38:23

Open Source Malware (OSM) addresses the gap in detecting intentional malicious open-source components by cataloging threats, de-obfuscating code, extracting indicators of compromise, and providing post-incident data, while tackling challenges like persistent malicious packages, limitations of traditional tools against interpreted languages, fragmented collaboration, AI risks, and the need for improved CI/CD security, audit tools, and balanced AI-human oversight.

Episode Description

Josh talks to Paul McCarty of Open Source Malware about ... open source malware. Paul explains why there aren't many good open source malware datasets...

Overview

The podcast discusses the development and purpose of Open Source Malware (OSM), a platform founded to address the gap in detecting malicious open-source components, such as GitHub repositories, packages, and extensions, which traditional vulnerability tracking systems like OSV and GHSA overlook. While these tools focus on accidental vulnerabilities, OSM specializes in cataloging and analyzing packages with malicious intent, providing actionable insights for both proactive protection and post-incident response. Key challenges highlighted include misaligned data models in existing vulnerability databases, limited incident-specific details (like threat intelligence or indicators of compromise), and the difficulty of analyzing deleted or obfuscated malicious code. OSM emphasizes community-driven contributions and transparency, unlike proprietary or corporately sponsored solutions, and aims to build a business around its unique value in open-source security.

The discussion also underscores persistent risks in the software supply chain, such as malicious packages persisting in private repositories or developer environments even after removal from public registries. Critiques of platforms like OpenClaw, which lack curated security measures, and the broader industrys tendency to overlook threats in AI-driven tools and AI agent workflows are emphasized. Security experts warn of escalating risks from AI agents misused for credential theft, privilege escalation, or unauthorized access, stressing the need for education and proactive defenses. The podcast calls for industry-wide collaboration to unify threat intelligence, improve registry curation, and address systemic gaps in security practices, particularly in CI/CD pipelines and AI integration, to mitigate emerging threats.

Recent Episodes of Open Source Security

17 Aug 2026 Maintaining EOL Open Source with Commonhaus and HeroDevs

"Explores open-source maintenance challenges, solutions for solo maintainers, and the role of organizations like Common House and HeroDevs in sustaining projects through financial, legal, and administrative support, emphasizing governance, dependency management, and enterprise-community collaboration to ensure long-term sustainability."

10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e

"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."

3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity

"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."

27 Jul 2026 Securing critical infrastructure with Josh Corman

"Cybersecurity faces escalating threats to critical infrastructure, requiring stronger OT security, IT-OT collaboration, proactive threat modeling, and resilience engineering to prevent real-world disasters."

20 Jul 2026 Abandoned open source with Josh Marpet

"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."

More Open Source Security episodes