
When you think about malware, you probably envision phishing emails or sketchy websites. But malicious open source - targeting software developers and their build systems - is becoming a top way that threat actors deliver malware. Just one 'npm install' can trigger payloads that steal information and credentials. Software supply chain attacks by state actors, ransomware groups, and freelancers are... more
| Publishes | Weekly | Episodes | 19 | Founded | 4 months ago |
|---|---|---|---|---|---|
| Number of Listeners | Category | Technology | |||

This week we talked about:
• TeamPCP arrests — Australian Federal Police and the FBI arrested Ruben Thomson (21) and Louis Gaebler (23) in Perth on TeamPCP-related charges. The arrests align with the OpenSourceMalware team's longstanding assessmen... more
This week we talked about:
Rust arrayref compromise tied to DPRK infrastructure: A compromised maintainer account published malicious versions of the arrayref crate, along with internment and append-only-vec, adding a typosquatted build dependency ... more
This week we talked about:
• Hacker Summer Camp trends. Jenn and Paul share observations from Black Hat, DEF CON, and BSides Las Vegas last week, including a maturing AI security conversation that has shifted to focus on where AI still falls short,... more
This week we talked about:
• New npm worm hits Keyv and cacheable. Jared Wray's GitHub account was compromised on Tuesday, and threat actors used it to publish a worm based on the open-sourced Mini Shai-Hulud malware. The worm spread to over 400 pac... more
People also subscribe to these shows.




If you want to know about software supply chain attacks, this is the show for you!
Key themes from listener reviews, highlighting what works and what could be improved about the show.
How this podcast ranks in the Apple Podcasts, Spotify and YouTube charts.
Apple Podcasts | #188 |
Listeners, social reach, demographics and more for this podcast.
| Listeners per Episode | Gender Skew | Location | |||
|---|---|---|---|---|---|
| Interests | Professions | Age Range | |||
| Household Income | Social Media Reach | ||||
A technically focused show that dissects threats in software supply chains, with a heavy emphasis on malicious open-source ecosystems, package management abuse, and attacker tradecraft. Episodes frequently cover npm, PyPI, VS Code marketplace, and other ecosystems, highlighting practical defense tactics, incident response notes, and community research efforts. A standout aspect is the dual-host format helmed by long-running researchers, who blend hands-on analysis with industry context, guest insights, and ongoing OpenSourceMalware project work. The show is likely valuable for security teams, developers, and threat hunters seeking actionable intel, tooling tips, and an understanding of evolving state-actor tactics in software supply chains.... more
Rephonic provides a wide range of podcast stats for The OpenSourceMalware Show. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to The OpenSourceMalware Show and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.
Rephonic provides a full set of podcast information for four million podcasts, including the number of listeners. View further listenership figures for The OpenSourceMalware Show, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.
Rephonic provides comprehensive predictive audience data for The OpenSourceMalware Show, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.
To see how many followers or subscribers The OpenSourceMalware Show has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.
These podcasts share a similar audience with The OpenSourceMalware Show:
1. Open Source Security
2. Risky Business
3. Darknet Diaries
4. AI Security Podcast
The OpenSourceMalware Show launched 4 months ago and published 19 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.
Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.
Rephonic pulls ratings and reviews for The OpenSourceMalware Show from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.
View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.
Rephonic provides full transcripts for episodes of The OpenSourceMalware Show. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.