Identifying Malicious OSS Across Ecosystems
CVE/FIRST VulnCon 2025 · Main Stage
Overview
This talk, delivered by Justin Smith of Microsoft's Open Source Security Team at VulnCon, shifts focus from traditional vulnerabilities to the pervasive and growing threat of malicious open-source software (OSS) across various package ecosystems. Smith highlights that while VulnCon often centers on CVEs and known vulnerabilities, a distinct and equally critical problem lies in outright malware masquerading as legitimate packages. The presentation outlines the motivations behind OSS malware, the limitations of traditional detection methods when scaled across multiple platforms, and introduces a novel research project named "OSsimilation" developed at Microsoft to address this challenge.

Key moments
- 0:00 Introduction: Shifting focus to OSS malware
- 1:20 Why OSS malware is a growing problem
- 2:40 Limitations of static and dynamic analysis
- 4:00 Novel approach: Analyzing OSS package metadata
- 5:00 Interactive game: Identifying 'crash handler' malware
- 6:10 Interactive game: 'PDF password protector util' (benign)
- 7:50 Interactive game: 'agent base' (typo-squatting malware)
- 9:50 Interactive game: 'prettier' typo-squatting malware
Identifying Malicious OSS Across Ecosystems
Speakers: Justin Smith, Senior Security Program Manager, Microsoft
Conference: VulnCon
YouTube: https://www.youtube.com/watch?v=qo8zG13I3dQ
Overview
This talk, delivered by Justin Smith of Microsoft's Open Source Security Team at VulnCon, shifts focus from traditional vulnerabilities to the pervasive and growing threat of malicious open-source software (OSS) across various package ecosystems. Smith highlights that while VulnCon often centers on CVEs and known vulnerabilities, a distinct and equally critical problem lies in outright malware masquerading as legitimate packages. The presentation outlines the motivations behind OSS malware, the limitations of traditional detection methods when scaled across multiple platforms, and introduces a novel research project named "OSsimilation" developed at Microsoft to address this challenge.
Smith's work focuses on proactively identifying and mitigating malicious packages across popular registries like npm, PyPI, NuGet, and the VS Marketplace. The talk emphasizes the alarmingly low barrier to entry for attackers, allowing them to publish malicious code that can gain access to critical build and production systems. By detailing real-world examples and the methodologies employed by the OSsimilation project, the presentation serves as a crucial call to action for organizations to re-evaluate and strengthen their software supply chain security against this evolving threat landscape.
The core message is clear: the open-source ecosystem, while a boon for development, is increasingly exploited by adversaries. Understanding how these attacks manifest, how they can be detected using metadata analysis and human intelligence, and what defensive measures can be taken, is paramount for any organization relying on open-source components. The talk effectively demystifies the complex world of OSS malware, offering practical insights and a glimpse into cutting-edge detection strategies.
Background
▶ Watch: Introduction: Shifting focus to OSS malware (0:00)
The proliferation of malicious open-source software is a direct consequence of the widespread adoption and inherent characteristics of the OSS ecosystem. As Smith points out, an astounding 96% to 97% of modern codebases incorporate open-source components. This ubiquity, combined with a remarkably low barrier to entry – most repositories allow anyone with an email address to publish packages at no cost – creates a fertile ground for attackers. With over 11 million individual OSS packages across numerous platforms, each potentially having many versions, there are ample opportunities for malicious actors to hide their code. Critically, these packages often gain access to sensitive environments, including build systems and production infrastructure, making them attractive targets for compromise.
The problem is exacerbated by a clear trend: the number of malicious packages is increasing year-over-year, growing in lockstep with the overall expansion of OSS. While malicious activity is observed across various repositories, npm stands out as the biggest target, followed by PyPI, according to data from the OSSF's malicious package dataset. This escalating threat necessitates robust and scalable detection mechanisms.
Traditionally, two primary approaches have been used to identify malware: static analysis and dynamic analysis. Static analysis attempts to predict code behavior by examining its structure, often employing compiler-like techniques to build abstract syntax trees and call graphs. While powerful, it can be computationally expensive and challenging to scale across the vast and diverse open-source landscape, especially when dealing with multiple programming languages. Dynamic analysis, on the other hand, involves observing code execution, typically within a sandbox environment, to log its runtime behavior. This method can catch most types of malware but is also difficult to scale, doesn't guarantee detection of all malware types, and frequently generates a large number of false positives, necessitating extensive human review.
The challenge of finding malware across multiple package managers further complicates matters. Both static and dynamic analysis tools are generally optimized for a small number of specific languages, making them inefficient for a cross-ecosystem approach. This limitation prompted Smith's team to explore an alternative, more generalized strategy: leveraging the metadata associated with OSS packages. Metadata, which includes information about the package, its authors, description, keywords, and versioning, offers a language-agnostic lens through which to identify suspicious patterns that might indicate malicious intent.
Key Findings
▶ Watch: Limitations of static and dynamic analysis (2:40)
The OSsimilation research project, as detailed by Justin Smith, yielded several key findings regarding the nature of OSS malware and effective detection strategies:
- Metadata as a Primary Indicator, Human Review as a Necessity: The talk conclusively demonstrates that package metadata, including elements like name, description, keywords, versioning, and associated scripts, serves as a powerful initial filter for identifying suspicious packages. However, automation based solely on metadata is insufficient. The "game" played during the presentation highlighted that while many suspicious metadata patterns correlate with malware, some benign packages can exhibit similar characteristics, and vice-versa. Therefore, a human in the loop is consistently required for accurate identification and to reduce false positives.
- Common Malware Archetypes Across Ecosystems: Despite differences in implementation details, attackers predominantly employ a consistent set of malware archetypes across various package managers. Smith categorized these into:
- Exfiltrators: Packages designed to collect and transmit sensitive or benign data from the local system (e.g., home directory information, DNS, IP addresses, browser passwords) to remote attackers, often via Discord webhooks or similar channels.
- Droppers: Packages that connect to remote systems to download and execute additional scripts or binaries, allowing for dynamic payload delivery and evasion of initial detection.
- Crypto Stealers and Miners: Malware specifically designed to steal cryptocurrency wallet credentials or utilize the victim's system resources for illicit cryptocurrency mining.
- Spam Packages: Although not traditional malware, these packages abuse the ecosystem for advertising, referral link loops, or other forms of unsolicited content, eroding trust and consuming repository resources.
- Evolving Attack Techniques Require Adaptive Defenses: The threat landscape is dynamic. Attack techniques continuously evolve, necessitating constant iteration on detection rules and techniques. Rules that once produced many results may become less effective over time. This underscores the need for continuous research, development, and adaptation in the security community.
- Platform Abuse for Fractional Gains: Attackers are highly opportunistic and will exploit any platform that allows them to automate money-making schemes, even if the individual returns are minuscule. Examples include the ad referral loops seen in npm spam packages and the abuse of the T protocol. The T protocol, designed to reward open-source contributors based on project dependencies (T-rank), was exploited by attackers who created tens of thousands of fake dependencies to artificially inflate their package ranks and receive crypto payments. This demonstrates that financial motivation, even for fractions of a penny, is a strong driver for widespread abuse.
- Collaboration is Key: Effective defense against OSS malware requires a collaborative effort between security researchers (like Microsoft's team), package manager operators, and the broader open-source community. Reporting and removal of malicious packages are crucial, but continuous innovation in detection and prevention is also vital.
These findings collectively paint a picture of a sophisticated and persistent threat, highlighting the critical need for multi-faceted detection strategies that combine automated metadata analysis with expert human judgment, and a commitment to adapting to new attack vectors.
Technical Deep Dive
▶ Watch: Interactive game: Identifying 'crash handler' malware (5:00)
The core of Justin Smith's talk delves into the technical methodology employed by Microsoft's "OSsimilation" research project, which focuses on leveraging package metadata for cross-ecosystem malware detection. This approach addresses the scalability limitations of traditional static and dynamic analysis when applied to the vast and varied world of open-source package managers.
The Power of Metadata Analysis
Metadata, in the context of OSS packages, refers to the descriptive information about a package rather than its executable code. This includes fields such as:
- Name: The package identifier.
- Keywords: Tags describing the package's functionality.
- Description: A brief summary of what the package does.
- Version: The release number.
- Author/Publisher: Information about who created or published the package.
- Repository URL: Link to the source code repository (e.g., GitHub).
- Scripts: Pre- or post-installation scripts (particularly relevant in npm).
Smith illustrated the utility of metadata through an interactive "game" with the audience, showcasing several npm packages with suspicious metadata patterns:
crash handler: This package demonstrated namespace confusion. While a legitimatecrash handlerexists within a specific namespace (@incom/reliability-kit), the attacker published an identically named package without the namespace. Suspicious metadata included blank fields and an unusually high version number for a package with no prior history, along with the presence of a post-install script.PDF password protector util: This example highlighted that suspicious metadata doesn't always equate to malware. It ran a Maven command (Maven clean package) on installation, which is highly unusual for an npm package. Despite this red flag, human review of the code revealed it was benign, albeit performing odd actions like calling out to a JAR file for password encryption. This underscores the necessity of human judgment.agent base: A classic case of typo squatting, where the attacker simply omitted the 'A' from the legitimateagentbasepackage name. The metadata showed a single, high version (7.11) and "post install nonsense" (malicious scripts). This was part of a larger campaign involving dozens of similar packages.HTB test-CLI: This package was presented as a potential red flag due to its name suggesting a command-line interface and the use of Rust packaged via npm. However, it was confirmed as benign, illustrating that unusual combinations of technologies or distribution methods aren't inherently malicious.prettiertypo squat: This was a blatant typo squat on the popularprettierpackage. The attacker even left the description spelled correctly while misspelling the name, making the intent clear. Crucially, it had the same repository URL as the legitimate package. This particular malware was notable because it included the malicious payload as a bundled binary within the npm package, making it detectable by many traditional antivirus solutions upon download.
These examples vividly demonstrate how metadata, especially when analyzed for anomalies, can quickly surface potential threats.
The OSsimilation Project Workflow
To scale this metadata-driven detection across multiple ecosystems, the OSsimilation project adopted a systematic workflow:
- Data Ingestion from Aggregators: Recognizing the impracticality of scraping every package manager individually, the project leverages third-party services that aggregate metadata from various repositories. Libraries.io was chosen for this purpose due to its useful API, which allows for regular retrieval of recently published packages. Other similar services mentioned include Ecosystems and Deps.dev.
- Registry-Specific Metadata Enrichment: While aggregators provide a neutral metadata format, some critical information is often specific to individual package managers. For instance, npm's install scripts are a notorious vector for malware, and this detail might not be fully captured in a generalized format. Therefore, after pulling data from Libraries.io, OSsimilation makes targeted requests to specific registries (e.g., npm) to fetch this additional, high-fidelity metadata.
- Logging and Rule-Based Alerting: All collected metadata, both generalized and registry-specific, is logged. This forms the basis for automated analysis. A set of predefined rules is then applied against these logs. These rules are designed to flag patterns identified as suspicious during the metadata analysis phase (e.g., blank descriptions, unusually high single versions, presence of post-install scripts, names similar to popular packages, specific keywords like "Azure" if impersonation is suspected).
- Human Inspection and Tooling: The output of the rule-based alerting system is a set of potential malicious packages. Crucially, these alerts are then subjected to manual inspection by security researchers. This human review is essential to filter out false positives and accurately identify true malware. During this phase, specialized tools (e.g., deobfuscators) are used to analyze the code if necessary.
- Reporting and Remediation: Once a package is confirmed as malicious, it is reported to the respective package manager owners, who are generally prompt in taking down the offending packages.
Malware Deep Dive Examples
Smith provided deeper insights into the code and behavior of identified malware:
crash handler(Exfiltrator): This package, identified via namespace confusion, contained code designed to collect sensitive system information. A snippet revealed it gathered data about the victim's home system, DNS configuration, and IP address. This information was then exfiltrated to a Discord webhook, allowing the attacker to monitor compromised machines from a private Discord channel.agent base(Dropper): This typo-squatted package employed obfuscated JavaScript code. While obfuscation is also common in legitimate minified packages, security researchers can use deobfuscators to reveal the underlying logic. The deobfuscated snippet showed a multi-stage attack:
- It connected to an Ethereum wallet to retrieve a C2 (Command and Control) IP address, a technique often used to obscure the true C2 infrastructure.
- It then downloaded a script from this C2 server.
- Finally, it executed the downloaded script. The obfuscated code also contained logic to adapt its payload based on the operating system, with the Windows-specific execution path highlighted.
- Spam Campaigns (Platform Abuse): Beyond traditional malware, OSsimilation also detects platform abuse. One notable campaign involved npm packages with READMEs designed to function as free web pages. These READMEs contained links that, when clicked, led victims into an endless loop of advertising referral links. Attackers generated fractions of a penny for each click, leveraging npm's hosting capabilities for free.
- T Protocol Abuse: A more sophisticated form of platform abuse was the manipulation of the T protocol. This protocol aims to foster open-source sustainability by making crypto payments to contributors based on their "T-rank," which is heavily influenced by the number of dependent projects. Attackers created packages with names like "Azured Swan" (often generated randomly) and then artificially inflated their dependency count to tens of thousands using fake projects. This allowed them to game the T-rank system and receive illicit payments. OSsimilation helped npm remove over 47,000 such packages, highlighting how financial incentives, however small, can drive large-scale abuse campaigns.
The OSsimilation project underscores that effective cross-ecosystem malware detection requires a combination of smart data aggregation, targeted metadata enrichment, automated rule-based analysis, and indispensable human expertise to combat the diverse and evolving tactics of malicious actors.
Demo / Proof of Concept
▶ Watch: Interactive game: 'PDF password protector util' (benign) (6:10)
While the talk did not feature a live, interactive software demonstration in the traditional sense, Justin Smith effectively utilized a conceptual "game" to serve as a proof of concept for the metadata analysis methodology. This interactive segment engaged the audience in identifying potential malware based solely on package metadata, mirroring the initial stages of the OSsimilation project's human review process.
The "game" presented five distinct npm package metadata examples, challenging attendees to determine if they were malicious. This approach vividly illustrated how specific metadata patterns can serve as strong indicators of compromise:
crash handler: This package immediately raised suspicion due to its completely blank description and keywords, coupled with an unusually high version number (e.g.,1.0.10000) for a new package. The audience correctly identified these as red flags. Smith later revealed this was a namespace confusion attack, where the attacker published a package with the same name as a legitimate one but without its namespace, and it contained a malicious post-install script.PDF password protector util: This example presented a package with a descriptive name but metadata indicating a post-install script that executed a Maven command (Maven clean package). This was highly suspicious for an npm package. However, Smith revealed this package was not malware, but rather performed unusual, albeit benign, actions. This highlighted the critical need for human review to differentiate between suspicious behavior and actual malicious intent, preventing false positives.agent base: This package's metadata showed a single, high version number and vague "post install nonsense." The audience quickly recognized this pattern. Smith confirmed it was typo squatting on the legitimateagentbasepackage, part of a larger malware campaign.HTB test-CLI: This package, while having a somewhat generic name, did not exhibit obvious malicious metadata patterns. It was confirmed as benign, demonstrating that not all packages with potentially ambiguous names are malicious, even if they use unusual distribution methods (like Rust binaries via npm).prettiertypo squat: This final example was a clear-cut case of typo squatting. The package name was slightly misspelled (partierinstead ofprettier), but the description was copied verbatim from the legitimate package. Crucially, it also shared the same repository URL as the genuineprettierpackage, a strong indicator of impersonation. Smith noted this package included its malware as a bundled binary, making it detectable by antivirus software.
Through this "game," Smith effectively demonstrated:
- The types of metadata clues that security analysts look for.
- The effectiveness of metadata as an initial filter for suspicious packages.
- The necessity of combining automated checks with human intelligence to avoid false positives and accurately classify threats.
- Common attack vectors like typo squatting, namespace confusion, and the abuse of post-install scripts.
This conceptual demonstration served as a compelling proof of the methodology's viability and the nuanced judgment required in identifying OSS malware.
Defensive Implications
▶ Watch: Interactive game: 'prettier' typo-squatting malware (9:50)
The insights gleaned from the OSsimilation project and the analysis of OSS malware provide crucial guidance for developers, security teams, and organizations aiming to bolster their software supply chain security.
- Enhance Developer Vigilance and Education:
- Scrutinize Package Names and Authors: Developers must be trained to carefully inspect package names for subtle misspellings (typo squatting) and to verify author credibility, especially for new or less popular packages. The
agent baseandprettierexamples underscore this. - Review Metadata Thoroughly: Pay attention to package descriptions, keywords, and versioning. Packages with blank or suspicious metadata, unusually high initial versions, or mismatched repository URLs should be treated with extreme caution.
- Be Wary of Post-Install Scripts: Understand that
post-installorpre-installscripts (especially in npm) can execute arbitrary code. Review these scripts before installation if possible, or use tools that flag their presence. Thecrash handlerandagent baseexamples are prime illustrations of this risk.
- Implement Robust Software Supply Chain Security Practices:
- Internal Package Registries: For critical applications, consider using internal or curated package registries that only allow pre-approved, vetted open-source components.
- Dependency Auditing: Regularly audit all third-party dependencies for known vulnerabilities (CVEs) and, crucially, for signs of malicious intent. Tools that leverage metadata analysis can be integrated into CI/CD pipelines.
- Pin Dependencies: Pin dependencies to specific, known-good versions to prevent automatic updates from introducing malicious code.
- Integrate Security Tools: Employ a layered approach using a combination of static analysis (SAST), dynamic analysis (DAST), and software composition analysis (SCA) tools. While these have limitations for cross-ecosystem malware, they are still vital for overall security.
- Antivirus/Endpoint Detection: Ensure endpoint security solutions are up-to-date and effective, especially against bundled binaries (like the
prettiertypo squat) and dropper-style malware that downloads executables.
- Leverage and Contribute to Threat Intelligence:
- Stay Informed: Keep abreast of new attack techniques and campaigns affecting open-source ecosystems. Resources like the OSSF's malicious package dataset and community reports are invaluable.
- Report Suspicious Packages: If a suspicious or malicious package is identified, report it immediately to the respective package manager to aid in its removal and protect the broader community. This collaborative effort is essential, as emphasized by Smith.
- Embrace Hybrid Detection Methodologies:
- Automated Metadata Monitoring: Organizations should consider implementing or utilizing tools that automatically scan package metadata for anomalies, unusual patterns, and known indicators of compromise. This provides a scalable first line of defense.
- Human-in-the-Loop Review: Acknowledge that automation alone is insufficient. Establish processes for security analysts to manually review flagged packages. This expert judgment is critical for reducing false positives and accurately identifying sophisticated threats.
- Continuous Adaptation: Develop a strategy for continuously updating detection rules and techniques as attacker methods evolve. What works today might be bypassed tomorrow.
- Understand Platform Abuse Beyond Traditional Malware:
- Resource Consumption: Be aware that even "spam" packages, like those involved in ad referral loops or T protocol abuse, consume repository resources and erode trust in the ecosystem. While not directly compromising systems, they contribute to a degraded security environment.
- Precursor to More Malicious Activity: Sometimes, platform abuse can be a testing ground or a precursor for more severe attacks. Maintaining a clean ecosystem benefits everyone.
By adopting these defensive postures, organizations can significantly reduce their exposure to the growing threat of malicious open-source software, moving towards a more resilient and secure software supply chain.
Key Takeaways
- Growing Threat: Malicious open-source software is a rapidly increasing threat, exploiting the low barrier to entry in package repositories and gaining access to critical build and production systems.
- Metadata is Key for Scale: Analyzing package metadata (name, description, version, scripts, authors) offers a scalable, language-agnostic approach to identify suspicious packages across diverse ecosystems like npm, PyPI, and NuGet.
- Human Expertise is Indispensable: While automation can flag suspicious packages, human review is crucial to accurately differentiate between benign anomalies and actual malware, preventing high false positive rates.
- Common Attack Patterns: Attackers frequently employ similar techniques across ecosystems, including data exfiltration, droppers (downloading and executing remote scripts), typo squatting, namespace confusion, and abuse of post-install scripts.
- Opportunistic Platform Abuse: Adversaries will exploit any platform feature for even fractional monetary gains, leading to widespread spam campaigns (e.g., ad referral loops, T protocol manipulation), which erode trust and consume resources.
- Layered Defense and Vigilance: Organizations must implement robust supply chain security practices, including developer education, rigorous dependency auditing, and a combination of automated tools and human oversight to defend against evolving OSS malware.
About the Speaker(s)
Justin Smith is a Senior Security Program Manager on Microsoft's Open Source Security Team. His primary focus is on identifying and mitigating malicious open-source software across multiple platforms, including npm, PyPI, NuGet, and the VS Marketplace. Prior to his role at Microsoft, Smith worked extensively in the application security space, where he was involved in building Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) products for .NET and .NET framework applications. His expertise spans both traditional application security and the emerging challenges of securing the open-source supply chain.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Smith delivers a competent, well-structured overview of malicious OSS detection that sits squarely in the threat-intel/case-study lane. The OSsimilation project is real work with real outputs — 47,000 packages removed from npm is not nothing — and the metadata-first, cross-ecosystem framing is a legitimate contribution to a problem space that deserves more systematic attention. The interactive 'game' is a nice pedagogical device. But the talk stops well short of the technical depth you'd want from a conference billed around vulnerabilities. The methodology is described at a conceptual level rather than exposed in full: no rule logic, no precision/recall numbers, no discussion of…
Heather Calloway (CISO) — SOLID
Justin Smith delivers a competent, technically grounded overview of cross-ecosystem OSS malware detection, with genuine operational value for security engineers working the supply chain problem. The metadata analysis methodology is practical and the examples are well-chosen. But the talk never fully surfaces the institutional consequences of what it's describing — who bears accountability when malicious packages reach production, what the governance posture of most organizations actually looks like against this threat, and what a security leader should do Monday morning beyond 'train your developers.' Useful for practitioners, not transformative for decision-makers.