Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Sararimen, Aaran Leyland - SWN #576

Security Weekly News (Audio)28mApril 28, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Sararimen, Aaran Leyland - SWN #576” inside PodZeus.

AI-Generated Summary

A major supply chain attack on the Python Package Index (PyPI) has compromised version 0.23.3 of a popular package with a backdoor info stealer, exploiting a GitHub Actions flaw to forge signed releases and distribute malware through legitimate channels. The attack, which leveraged a malicious comment in a pull request to inject shell code and steal credentials, underscores the growing sophistication of software supply chain threats. Meanwhile, the Glassworm campaign has expanded its reach by planting 73 dormant extensions on OpenVSX, with six now active and exfiltrating crypto wallet data and GitHub credentials. Medtronic confirmed a cyberattack on its corporate IT systems, though it downplayed impact—raising concerns about transparency in critical infrastructure breaches. As AI tools like GitHub Copilot shift to usage-based billing, a new 'financial threat' emerges: users addicted to free AI may face steep costs, echoing past tech lock-in traps. The episode also highlights how AI accelerates existing attack patterns—reducing dwell time to just 22 seconds—while foundational weaknesses like poor patching and over-permissive access remain the root cause of most breaches. The host warns that 'old problems are new again,' urging organizations to prioritize cyber hygiene over AI hype.

Key Takeaways
1

Rotate all secrets and restore from a clean snapshot if you installed PyPI package version 0.23.3 due to a forged backdoor release.

2

Attackers exploited a GitHub Actions flaw via malicious pull request comments to steal tokens and publish malware under official release pipelines.

3

Glassworm now uses dormant extensions on OpenVSX that activate later with malicious dependencies, evading detection through typo-squatting and stealthy activation.

4

Medtronic confirmed a cyberattack but downplayed impact—highlighting the need for transparency in critical infrastructure breaches.

5

AI is not replacing old threat models but accelerating them: dwell time dropped to 22 seconds in 2025, and exploit windows are now days, not weeks.

…and 3 more takeaways available in PodZeus

Chapters
0:00
2 min

Welcome & 50K YouTube Milestone

Doug White celebrates reaching 50,000 YouTube subscribers, reflecting on the community's growth and the show's mission to make security discussions engaging and accessible.

2:00
4 min

PyPI Supply Chain Attack via GitHub Actions

They posted a malicious comment on a pull request and that exploited a GitHub action script injection flaw, which caused the workflow to execute shell code.

Highlight
6:00
4 min

Glassworm’s Dormant Extension Campaign

Nearly 100 extensions for this were found back in March along with 20 sleeper extensions that were posted but had no comments.

Highlight
10:00
4 min

Medtronic Cyberattack & Transparency Concerns

I don't know at this point, either not much actually happened or a lot happened and they're not saying.

Highlight
14:00
4 min

The Rise of AI-Driven Financial Threats

GitHub Copilot’s shift to usage-based billing creates a new 'financial threat'—users addicted to free AI tools may face steep, unexpected costs.

High-Impact Quotes
They posted a malicious comment on a pull request and that exploited a GitHub action script injection flaw, which caused the workflow to execute shell code.
Doug White2:52
Viral: 85.0
I don't know at this point, either not much actually happened or a lot happened and they're not saying.
Doug White10:56
Viral: 78.0
If adults want to do that, no worries. Go crazy. That's your money and your problem. But these are games that appeal to kids.
Doug White27:39
Viral: 75.0
Speakers

Host

Doug White

Guest

Aaron Leland
Topics Discussed
software supply chain attack95%cyber hygiene92%github actions vulnerability90%info stealer malware88%glassworm campaign85%medtronic cyberattack80%nft gaming scams78%ai usage-based billing75%
People & Brands

Doug White

person

15xNeutral

PyPI

product

8xNegative

Glassworm

other

7xNegative

GitHub Actions

product

6xNegative

OpenVSX

product

5xNegative

Aaron Leland

person

5xNeutral

Medtronic

organization

4xNeutral

GitHub Copilot

product

4xNeutral

Townstar

media

3xNegative

Elf Smasher

media

2xNegative

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Sararimen, Aaran Leyland - SWN #576” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime