meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, August 17th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 17 August 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. PowerShell Gallery Malware; Windows Time Issues; Malicious QR Codes; Citrix Scanner

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, August 17, 2023 edition of the Sandton and Stormsenders Stormcast.

0:07.8

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.2

In the past, I talked a lot about malicious packages in Python's PIPP ecosystem or the Node.js NPM ecosystem. But well, they're not alone when it

0:24.6

comes to malicious packages. Researchers from Aqua Nodulus did publish some work looking into

0:32.3

malicious modules in the PowerShell Gallery. PowerShell Gallery is maintained by Microsoft, and as the name suggests,

0:40.7

does contain PowerShell packages. So lots of useful tools here that you can download,

0:47.6

but not every package that you find is actually useful. Some of them are outright malicious,

0:53.4

and it appears that some attackers have

0:56.4

discovered good old tricks like typo-squadding can be used in order to trick users to download

1:03.2

their malicious package. And it doesn't help that developers don't always sort of adhere to the

1:08.9

informal conventions when it comes to package naming.

1:13.3

The researchers here point out that many, many packages that deal with Asia start the name with

1:20.3

ACDOT. And there is a very popular package called ACTable, well, without the dot.

1:29.2

Now, they as a test uploaded a package ACDOT table, which would sort of more match the more common

1:36.9

convention here.

1:38.3

And of course, it was accepted, it was published, and made available for download. Aqua did publish this particular

1:46.9

package with a callback so they could detect if it was actually being used, and yes, they immediately

1:53.0

did notice multiple organizations downloading and using this typosquotted version of AC table.

2:01.1

So just like with Python, Node.js, or any language that offers a repository like this,

2:07.3

where anybody can upload packages, well, be sure that you know what you're downloading.

2:14.0

Be careful.

2:15.0

And in particular, the type of squatting part here is something that is avoidable if you are

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.