Shai-Huludの系譜は止まらない?巧妙化する直近のソフトウェアサプライチェーン攻撃を読み解く
This time, we'll be discussing recent software supply chain attack campaigns that follow in the footsteps of Shai-Hulud. Based on research blogs from JFrog, StepSecurity, Socket, and others, we'll explore the sophisticated technical aspects behind attacks ranging from "IronWorm," a Rust-based attack with an eBPF rootkit, to "Miasma," which exploits binding.gyp, and "Hades," which exploits Python's .pth files, as well as the techniques for countering them. 📝 Today's Topics 00:00 Opening 00:30 The Rainy Season and Takumi Plushie 01:11 Today's Theme: Software Supply Chain Attacks 02:19 IronWorm: A New Type of Sample Where Rust-Written ELF Binaries Fall Down 13:13 Miasma: A Worm Attack Targeting npm Packages 17:02 RCE Exploiting the Auto-Execution Specification of binding.gyp 21:51 Hades: The Shai-Hulud Legacy Spreads to PyPI 25:52 Auto-Execution at Python Interpreter Startup Exploiting .pth Files 31:09 Countermeasures on the Defendant Side: Anti-Sandbox Bypass Using Decoy Tokens 34:00 Announcement of an Event for OSS Developers 36:00 Discussion of Cooldown Periods in RubyGems 36:11 Introduction to cicd-sensor 38:05 Ending 📂 Articles/Websites Referenced/Introduced: IronWorm: Shai-Hulud's rustier cousin (JFrog Security Research) https://research.jfrog.com/post/iron-... Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp (StepSecurity) https://www.stepsecurity.io/blog/bind... Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave (Socket) https://socket.dev/blog/shai-hulud-de... What Should OSS Developers Do Now? Considering Software Supply Chain Intrusion Prevention Measures (connpass) https://flatt.connpass.com/event/395359/ Cool down before you install: give new gems a few days to be vetted (RubyGems) https://blog.rubygems.org/2026/06/03/... cicd-sensor/cicd-sensor (GitHub) https://github.com/cicd-sensor/cicd-s... 🤔 What is Ultra Thinking? This is a video podcast where engineers from GMO Flatt Security, who "support the backs of engineers," chat about the latest topics in product security and the development of Takumi's services. 🎧 Also available on Spotify: https://open.spotify.com/show/4V3QvwB... X: https://x.com/flatt_security #ultrathinking #security #supplychainattack #eBPF #npm #PyPI #Rust

ゲストicchyさんと振り返る、アンチウイルスを"オラクル"にした攻撃手法と、AI時代も人間が強い「発想」

【公開会議】cicd-sensorのこれから。開発者rungさんとTakumiチームで考える、OSSと企業の連携

【1日密着】Claude Codeに取り憑かれたエンジニア|その衝撃の開発手法に迫る

【AI勉強会】国会議員がバイブコーディングに挑戦!指示はチャットだけ?15秒で完成!? "体感"が政治と未来を変える #チームみらい【安野貴博事務所主催】

Reflecting on the Reality of Pwn2Own and kernelCTF in the AI Era with Participants

$500,000 in 3 months by having AI find Google vulnerabilities? Decoding the method and Apigee cro...

No Boss, No Money: The Raw Reality of China’s Gen-Z Freelancers

【安野貴博xPKSHA上野山勝也】AIネイティブ時代の生存戦略/地頭はAIに食われる/残るのは欲望する力だ | Startup Aquarium 2026

The DRAM Crisis: 600% Price Increases by Micron, SK Hynix, & Samsung

The Scariest Chart in Electrical Engineering

Claude Mythosは本当に特別なのか?Project Glasswingの進捗と他モデルとの比較を深堀る会

The Unity Tutorial For Complete Beginners

Decoding the Claude Code Vulnerability Article & AI Sandbox Talk 【Ultra Thinking #1】

Ulrich Siegmund spielt diese Aufnahme ab – und plötzlich steht Merz mit dem Rücken zur Wand!

Don't Hang Up On AI Scammers. Do THIS Instead.

Complete Terraform Course - From BEGINNER to PRO! (Learn Infrastructure as Code)

【ガチ検証】社長もAI。人間ゼロの会社に100万円託した結果が…【Claude / OpenClaw】

なぜデータ連携は失敗するのか?

Hands-On Cybersecurity and Ethical Hacking – Full Course

