Hacked - The Lorebook Cult
Episode Date: May 16, 2025Content warning: This episode contains descriptions of exploitation, self-harm, and abuse. Listener discretion is advised. A network called 764 has turned abuse into currency. It spread through Disc...ord, Telegram, and gaming platforms—built around “lorebooks,” collections of coerced violence traded for status. In a strange twist, this harm group has connections to cybercrime groups we've covered on this show before. Note: I was recording in an office, which between that and the subject matter, explains why my tone is pretty hushed in this one. Hacked is brought to you by Push Security—helping companies stop identity attacks before they happen. Phishing, credential stuffing, session hijacking—Push tackles it right where it starts: in the browser. Smart, seamless, and built for how people actually work. Check them out at pushsecurity.com. Learn more about your ad choices. Visit podcastchoices.com/adchoices
Transcript
Discussion (0)
Heads up, listener discretion is advised.
This story contains depictions of abuse, including self-harm and exploitation of minors.
I think a good way to understand this story is to start with the concept of lore books.
In certain very dark corners of the internet, lore books are a kind of currency.
They're how members join, they're how they earn status, they're how they move up.
A lore book is a collection of files, photos, videos, and screenshots, documenting harm.
sometimes physical, always psychological.
These are unfortunately some specific examples.
A lore book might contain photos of a person cutting a username into their skin.
A pet being harmed or a victim being coerced into something explicit.
The more extreme the material, the higher its value inside of these groups.
That's a lore book.
A portfolio of evidence of abuse.
I think we're all unfortunately aware that they're like dark corners of the
internet that exists where this kind of exploitation is produced, traded, and consumed.
But in those communities, the abuse material is kind of the end goal. It's the product. It's a
marketplace for that kind of thing. What makes this weird is that in groups like 764, which is
what we're talking about today due to some recent arrests, the abuse isn't the entire point.
It's more like a tool, kind of a mechanism used to manipulate.
to initiate, to radicalize, and to indoctrinate someone into joining what's basically a cult.
764 is a decentralized online abuse network where members coerce mostly minors into acts of abuse
self-harm and violence, and then trade that content as a digital currency.
It started on Discord.
It's spread to telegram, Roblox, Minecraft.
And while it might look on the surface like a grooming ring, which, you know, it's a
it is, its structure operates more like an online extremist movement, one that builds loyalty through
obedience, tests boundaries through cruelty, and rewards participation through this really rigid
hierarchy. To give a little bit of evidence that we're dealing with something different here,
the FBI has now opened more than 250 active investigations into 764, and federal prosecutors
are beginning to treat the network not just as a child exploitation ring, but as a domestic
terrorism threat due to the extremism and cult-inspired structure it has. It's happening in the U.S., Canada, Romania, Germany, the UK, Turkey.
Victims have been identified across three different continents. And as dark as it is, I think this story would still land within our wheelhouse as it stands.
But here's where it starts to get really odd. This isn't actually the first time we found ourselves circling this group on this show.
We just didn't know it at the time.
764 is a small part of a broader ecosystem known as the comm.
It's a loose network of cybercriminal clicks that includes like sim swappers, data brokers, social engineers.
Classical, just cybercrime, nothing to do with harm or abuse, many of whom have been tied to really high-profile attacks that we've covered on this show.
The comm, and again, this is not 764, but the larger org was tied to the MGM Resorts Hack, the snowflake breach, taxpayer groups like lapsis and scattered.
spider. 7-6-form is an online harm cult. Those are cybercrime groups. Some recent reporting from
spots like Krebs and Wired has revealed that at times throughout that history, it was the same
people in both. And that overlap kind of really matters because what we're starting to see now
is a growing intersection between cybercrime crews and this harm-based extremist model.
The circles of the Venn diagram aren't touching too much, but the fact that they're touching
at all is alarming.
People using extortion tactics developed in cybercrime forums to recruit victims into this
cult-like environment.
In April of this year, two alleged court members, Leonidas Vargianis, a U.S. citizen living in
Greece, and Prasanne Nepal from North Carolina, were arrested and charged with running one
of the group's most violent subgroups, which is why we're talking about it now.
So let's dig into it.
The Rise of 764, from a teenager's discord to a global cult of digital abuse and the growing convergence between online harm, radicalization, and cybercrime.
You're on hacked.
How you doing, Scott?
Pretty good.
Pretty good.
This story sounds like it's going to be pretty intense, but I am good.
How are you doing?
Yeah.
I'm doing okay.
I definitely spent quite a bit of time reading about a pretty dark thing,
but it's an interesting one, and it seemed pretty important.
I'm intrigued.
Like, obviously, you know that stuff like this exists on the Internet.
You know that there's like dark, there's dark souls out there,
not the game reference, but, you know, the people reference.
There's dark souls out there.
And there's like corners where those dark souls hide in the Internet.
You kind of have a gut check that like if there's something that could happen on the internet, it probably is happening on the internet.
I'm fascinated by the overlap to cybercrime.
That's where it gets me because to me those two things don't typically go together.
Like to me, completely.
You know, to me young cyber criminals or hackers or people that I assume are problem solvers and, you know, interested in challenges and overcoming things.
and they're kind of pursuing it from that angle.
I don't see them.
But I guess in every bell curve,
there's three standard deviations
from the mean either way.
So it's like,
if a community is large enough,
you can assume that there's representation
from every other community inside of it.
I think that's a good way putting it.
Like,
in order to do a lot of the stuff we cover on this show,
in order to be a problem solver,
a hacker,
a puzzle kind of cracker,
you have to be willing to break things.
And there's always, you know,
say,
5% of people are willing to break something in order to do that goal. We've kind of seen stories
like this where 5% of them are in it for the breaking. I think what this is is that same ratio,
but maybe seen on the social engineering side. Or more often than not, people are willing to manipulate,
betray trust, but it's normally part of a larger project. The betraying of trust and manipulating
people and getting control that way isn't the end. It's a mean. And I think what we're seeing here is
like, well, what if a community spun up where that was the end?
That was the thing they were trying to do was the social coercion.
There was no point to it other than the control.
Yeah, so I guess to carry on the analogy of breaking into things and breaking things,
maybe you're just figuring out how to break humans, which is kind of what it sounds like.
There's been some really good reporting by this.
Wired has done a bunch, Krebs on security's done a bunch.
was really who made the connection between this group and the calm, which again is, to be clear,
not a harm group. This is a cyber crime group that has connections to this. But CBC did some
really good reporting. And to your point, what they found was that it was, the reason this is going
after minors is mostly just because they're easier to manipulate and to break. Sure. The minor is
almost incidental. It seems like if they could be doing it to adults, they would be. It's more about
can you trick a person and dominate them in that way remotely over the internet. And kids are
just an easy target and this is not a cool group of people. I feel like that's a, I don't know,
I was at the mall yesterday and I was firsthand saw teenage angst. It's not often around me. I'm not
often surrounded by minors, but I went to the Apple store to pick something up and
got the firsthand display of teenage danks all around me.
And I remember those days.
I remember a junior high high school.
I remember your biochemistry is all messed up and everything's the most important thing.
And the funny thing is, when you get old like us, high school junior high is like such
a tiny little fraction of your life.
But when you're in it, it feels so important.
because you're biochemically, you know, kind of messed up.
You're vulnerable.
You're vulnerable.
Totally.
You're really vulnerable.
Yeah.
It makes things like social engineering a lot easier.
And then as we've seen in, again, social engineering in cybercrime contexts,
there's like a compression of sunk cost where you're already two steps into something.
And it feels like I've already come so far.
It's like, no, you've just been on a phone call for 10 minutes.
You can hang up.
You can back away.
You haven't, you're right where you started.
But when you're young, that's accelerated.
And then when these groups slowly start to bring people in and indoctrinate them with increasing levels of,
you've already done this, and now you've already done this, there's a little bit of a cycle that starts to develop.
So like I said, we're going to talk about this, then we're going to take a break,
then we're going to talk about some other stuff on this episode, brought you by push security.
So in April, U.S. law enforcement arrested two men accused of leading a group called 7-6 Inferno,
which is a faction of 764, Leonidas and Person, who I mentioned.
According to statements from the Department of Justice, both men helped direct operations targeting minors using blackmail extortion, helped create and distribute these lore books, these graphic packages of evidence of abuse, traded this content inside of these communities to build credibility and to recruit other people's into it.
The DOJ has labeled this a, I find this interesting language.
It's a nihilistic, violent extremist network, which is not.
language that is normally used in these kinds of cases, but is very seemingly accurate to the groups
like tactics and ideology. The FBI's counterterrorism division is now looking into it.
It's driven. It looks, there's a good quote from Alison Nixon. She's a researcher at Unit
221B. It's a com related crime way that's driven by a small, small number of highly prolific
actors. Um, so rests seem to work because this isn't a huge crew of people, but they are
doing this so aggressively and spending so much time in it that there's a relatively small
number of people that seem to be behind it. So as I mentioned in the intro, there's this larger
digital ecosystem called the comm. It's an umbrella term that encompasses a bunch of different
organizations. A lot of it are just doing cybercrime, data brokering, sims swapping. But then it
starts to intersect with these other groups like cult and courtlyke society and I wouldn't even
get into all of their names because the names alone are gross. But there's just overlap between
these two different groups. The overlap became especially clear in the aftermath that the
2023 ransomware attack on MGM resorts carried out by Alfa V and Blackcat. A 17 year old
British hacker using the handle at Hawley claimed credit for the intrusion and pretty quickly
researchers started discovering that the same telegram account was active in the 764
or linked harm channels where Holly was actively trading these lore books,
which is how we started to see some of these connections.
I think, can you explain the comm to me?
Like what makes up the comm?
Krebs has a really good answer to that, I think.
I'll just quote them here.
Collectively, this archipelago of crime-focused chat communities
is known as the comm,
and it functions as a kind of distributed cybercriminal social network
that facilitates instant connection.
But mostly, the calm is a place
cybercriminals go to boast about their exploits and standing within the community or to knock others down a peg or two.
Topcom members are constantly snaming over who pulled off the most impressive heists or who has accumulated the biggest pile of stolen virtual currencies.
As often as they extort victims for financial gain, members of the comm are also trying to arrest stolen money from their cyber criminal rivals, often in ways that spill over into physical violence in the real world.
There are action figures.
It's a whole thing of the comm.
It's an online community.
Social network seems like a good term for it.
Like a criminal, a dark criminal,
I guess it's like a modern manifestation of the dark web.
Totally.
Yeah.
With like a dark criminal social network.
Yeah.
Gameification and points and clout.
Yeah.
Churping each other and bragging and someone else brags back so you get mad and you got,
it's exactly that.
So 764 particularly,
at least starts with a guy named Bradley Cadenhead,
he was a teenager from Stephenville, Texas.
He was a troubled guy.
Caden had founded a Discord server in 2020
named after his zip code prefix 764.
He used aliases like Felix and Brad 764
and created the space where people, obviously, miners,
based on the context, were lured into the community
through Minecraft, Roblox,
and gradually coerced into increasingly extreme acts
which they were told to document and share there.
Cadenhead was finally arrested in August 2021 after Discord flagged him for 58 times for uploading abuse material.
When police seized his phone, they discovered dozens of abuse files and images of his username, like literally carved into people's bodies.
In 2023, he was sentenced to 80 years in prison.
764 is Stevenville, Texas.
When I first heard the group name, the first thing I did was converted to letters.
Like so many things.
Yeah, sure.
Yeah, 764 is G.
FD, which could mean anything, but I was intrigued to hear that it was based on an area code
because I thought it would be something more subvertive.
Yeah.
It's also not good operating.
Like I'm glad it's not good operational security.
This person should not be in the public.
And I would imagine that that probably helped lead to his arrest at a certain point.
But a postal code isn't exactly on the down low.
Exactly.
I'm looking up how many people live in Stephenville, Texas.
20,000 people.
It's actually a pretty small pool.
Yeah, yeah, we've narrowed it down.
Yeah, 100%.
And there's a lot of traffic coming from this one house.
So Cainhead gets arrested and a bunch of new people from the community
sort of level up into being leaders.
There's recurring motifs here.
And I think you can kind of see it in the larger manifest of this,
which is like there isn't really, it's a, the point of the cult isn't a charismatic leader.
The point of the cult isn't a story about what's going to happen to the world.
The point of the cult is that like we use sadism and harm to control people.
It's like a nihilistic kind of philosophical group.
And as such, other nihilistic philosophies seem to be drawn to it.
Duck slash Gore Butcher, otherwise known as Angel Louise Almeida.
We was also arrested a floor in a man with a violent criminal history, a devoted
follower of the Order of the Nine Angles, which is a satanic neo-Nazi cult.
It's very interesting to see what other groups are drawn into this.
When he was arrested in federal detention, Al-Meda managed to post from a contraband
phone and threaten a courtroom full of people saying, quote,
when I get out of here, I'm a kill all of y'all.
So.
Sure.
Yeah.
Just a crackerjack crew of folk.
Yeah.
Maybe it's my own innocence, but like I don't, I'm learning so many words right now.
I know.
And I'm leaving most of them out.
That's the really wild thing.
Like, I have my notes.
And they're made up of a bunch of different documents.
I had the unpleasant experience of reading.
And I'm leaving out a lot.
Again, if you want full kind of, not gross detail,
but if you want to really understand this, Krebs' coverage was admittedly very, very good.
Wired has done some great work.
And there's a 40-minute CBC doc on it that is worth watching.
It's a rough watch.
Crazy.
Yeah.
I'm just like reading about cut signs.
Yeah.
So let's jump into that then.
Why don't we?
Why don't we?
Because I've unleashed this on us.
Hopefully everybody's having a great morning out there.
Yeah.
Hope you all are doing good.
Yeah.
That was,
yeah.
So like you mentioned,
there's cuts.
So let's zoom out a little bit on that.
It's a gamified abuse cult is a pretty good way of understanding this.
There's social status gain through coercing people into these like increasing
levels of brutality and then getting them to post it.
And those tools as part of this, like we talked about Laura books a little bit,
fan signs, which is their sort of internal language for photos and videos documenting
these different acts of like abuse, abuse, and then cut signs, which is, as we have alluded
to multiple times, the act of carving a username into someone's body.
Or doing it to yourself to prove that you've been completely manipulated.
and are part of the...
Which is the sort of escalating levels of obedience
that are asked by this structure,
typically in a few cases,
and we'll talk about this,
result in people then being asked to...
Well, the next act of obedience isn't showing what you'll do.
It's getting someone else into this.
Totally. It's pyramid scheme.
It's pyramid scheme stuff.
It's called structure.
It's all the exact same psychology.
It's that once you've social engineered one person,
can you social engineer them into social engineering
three other people?
And the thing kind of continues down.
word forever. Luckily, luckily is the wrong word. There's a, a brittleness to this because the
harm is so extreme that it simply can't spread in the way that certain things would. Most people
just won't cut a username into their body. Most people won't just document something that
horrific, which again is why I think minors are targeted. So I read Helter Skelter as a kid,
a book about, Manson. Manson called.
And I can't help but feel like this is some modern day dark reincarnation of that.
A hundred percent.
And that used like aesthetics of cultural symbols for like evil and daint.
Like there was like an edge lordiness to it.
Like you got to talk about the devil and Nazi stuff because that's the scary stuff.
And it's like, is it relevant to this?
It's like that's not relevant.
It's that it's the scary thing.
It's the darkest thing we can think of.
And that's kind of all part of it.
And it's why you see someone like gore butcher wearing his satanic neo-Nazi
called shirt.
And that's the best of his shirts.
I'm not even joking.
There's worse shirts implicated.
You've seen his closet.
His closet is part of his evidence.
There's literally like two garments of clothing mentioned in the court documents.
And the satanic neo-Nazi one is the more tasteful of the two.
Like, so we're talking about this because there were these two.
two most recent arrests. We've already talked about a series of other arrests that have taken place.
It's still going. There's dozens of these channels still active on Telegram.
Reporting on Discord band 130 groups with 34,000 accounts in 2023.
There's still researchers are finding stuff on Instagram and meta platforms that are
connected to this SoundCloud weirdly has is hosting playlists that seem to reference like
insider 764 lingo.
And then Roblox and Minecraft
still seem to be the top of the funnel
for bringing people into this.
It's just a concentrated pool of miners
hanging out that you can go to and bring over.
Great way to repurpose like business development
sales lingo.
The top of the funnel.
It's like, oh, we use Roblox.
Tons of vulnerable 12 year olds in there.
To do what?
We move them from there into Discord
where we re-socialize them.
And then, you know, we advance them.
The ones that are willing to advance
in the queue, we get them into the private telegram channels.
And, yeah, then we document harm.
Their journey.
Their user journey.
Their user journey.
So it seemed relevant because of A, that connection to the comm, the larger cybercrime
hacking group and the fact that these two larger figures, Leonidas and Prason, were
recently to be arrested.
They were, according to the U.S. Department of Justice, directing and managing operations
for 7-6-Ferno, just one of these subgroups.
They were actively on the ground targeting miners distributing this material, compiling and trading these lore books.
Nepal was arrested in North Carolina on April 22nd. Vargianis was arrested in Greece on April 29th.
US is currently working on his extradition at the time of recording.
The FBI affidavit described both men as core figures in the ongoing structure of 764.
And it also references like their leadership role across not just that group, but multiple different platforms.
They were doing this like, I can't say that they were doing this full time, but they were
actively organizing across a telegram channels and discord channels. They were in the games
themselves. It's a extension not just of these like online communities where social engineering
is prominent, but the same kind of thing that you, I think you were right to bring up Manson,
where this like nihilistic violent extremism, how does it live online? What does it look like
in a modern digital context? And it seems like the answer to that is something like 7, 64.
Great. Yep. I feel like.
I don't normally feel like we need to do any kind of public advisory warningy type thing.
But this one seems heavy enough that, yeah, if you think this could be happening to someone
in your life and you're in the States, tips.fbi.gov, 988, suicide crisis hotline,
you can call her text. There's 988 lifeline.org. Like, if you know someone and you think
they need help, please, please try and help. I would imagine that any parent,
watching this show knows the importance of maintaining a like tech literacy parity with your child,
which is tough, but increasingly pretty important. But I think this is also just a really
good reminder of that is that you should probably, you should aspire to know as much about the
internet and technology that your kid is using as your kid does. And I know that's not always possible.
It certainly wasn't possible when I was a kid. Yeah. But it's still pretty dang good idea.
Yeah, no kidding.
I'm surprised, this is going to sound terrible,
but I'm surprised that the police forces are capable and with it enough to engage.
I kind of have a perspective on police, which is maybe not accurate,
but I don't see them like the Canadian police, the RC&P, American police and state troopers.
I get that the FBI and the NSA and the CIA and, you know, Canadian Secret Service,
has a more tech literate departments,
but for general policing,
like I kind of surprised
that they actually have the competency
to rip through this.
But I guess nowadays,
like I think back to our campus,
campus ethic.
Remember when we talked about like...
Yeah, we had an episode
where we discussed
kind of like monitoring of social media
by campuses to kind of
make sure that they knew the ongoings.
And I guess Telegram is
probably that new platform, not for campus protests, but like for everything on the internet.
It's like you need to be kind of monitoring telegram channels to see what's going on, what's being
planned, what's being discussed. Like every group that I can think of that's, I wouldn't call them
extremists, but I'll say that they have moderate to extreme views. Like if there are two standard
deviations either way on the bell curve, uses telegram as a communication.
this platform. So it's like I imagine the policing and law enforcement departments have really
grown their ability to track and monitor telegram. Yeah, I think the dedicated cybercrime divisions
inside of law enforcement are definitely a growing thing. Like I think just a lot of crime takes
place on the internet. And then the other thing I would attribute to this is that when you think about
the thing about trying to keep an online physical abuse, nihilistic death cult secret
is that there tends to be a lot of physical evidence of it.
Like you have kids with like, again, it's dark, but it's like you have kids with like self-mutilation
and dead pets.
It's like there's simply signs that something is wrong.
And if all this happened in a bedroom with a computer and a phone, it's like, yeah,
there's evidence.
Not even that.
that evidence is then collected, categorized, and put into lore books, which are essentially
like legal evidentially like portfolios. It's like a dossier of evidence. I think is how we
describe it in the introduction. It's like it's not, it's evidence of a crime that took place,
but in a weird way, the victim, the perpetrator of some of the crime is also very, I mean,
a much realer sense of the victim. Yeah, yeah, yeah, yeah, yeah. Yeah. Which gives that culty vibe.
It's extremely.
The Manson vibe.
It's a heavy one.
So we're going to do some ads now.
And then we're going to shake this off.
And then we're going to talk about something completely unrelated.
I almost feel like we should flip the episode, but this is the end story because it is so heavy.
It's like if you're still with us.
Now we're going to talk about this.
The next.
Now we're going to talk about like library vulnerabilities and popular software.
It's going to be much more chill, much more fun.
Because I don't have the editing capacity to flip-a-roo this whole episode.
So we are going to lead with the giant downer, probably.
Hopefully you're still here.
Hopefully you're still here.
And we'll see after the break.
Identity attacks, fishing, credential stuffing, session hijacking, account takeovers.
Are the number one cause of breaches right now.
But both security tools still focus on endpoints, networks, and infrastructure.
Meanwhile, the browser, the actual place where we're working, has been ignored.
Push changes that.
They built a lightweight browser extension that observes identity, activity in real time,
gives you visibility into how identities are being used across your whole organization,
like when login skip multifactor authentication,
when passwords are reused,
or when someone unknowingly enters credentials into a spoofed login page.
Then when something risky is detected,
push can enforce protections right there in the browser.
browser, no waiting, no tickets.
And it's not just about prevention.
Push also monitors real-time threats like adversary in the middle attacks, stolen
session tokens, and even new techniques like cross-IDP impersonation, where attackers bypass
single sign on a multifactor authentication by essentially setting up a fake identity provider
for your company.
The way to think about it, it's kind of like EDR, but in your browser.
Team behind it, they're all offensive security pros.
They publish some of the most interesting identity attack research out there, like the
software as a service attack matrix, which breaks down.
exactly how these kinds of threats bypass all those traditional controls. Identity is the new
endpoint and push. Our proud sponsor push is treating it that way. Check them out at pushsecurity.com.
Think about the last time you heard a breach story on this show. It always starts the same way.
Someone somewhere saw something too late. An alert buried, a signal missed, an SOC that just
couldn't keep up. Arctic Wolf set out to solve that
problem by rebuilding security operations from the ground up for a world where attackers are already
using AI. They created the Aurora superintelligence platform, a fully agentic system powered by the
swarm of experts. Instead of single-purpose bots or lucky-guess LLMs, this swarm is full of
deterministic agents that handle whole entire workflows. Humans stay in the loop and on the loop
to validate the critical decisions and keep everything trustworthy, and all of this is just off
running on their secure operations graph, a constantly updating intelligence engine.
fueled by more than 9 trillion telemetry events every week and over a decade of real-world incident response.
The system reasons on real signals and real context not synthetic training data.
And the result is the new Aurora Agent SOC.
It's the first SOC that is agent led by design.
You get agents that coordinate, agents that investigate, agents that respond at machine speed,
and hundreds more that automate the repetitive work that normally buries human analysts.
Arctic Wolf didn't try and bolt AI onto an old model.
They rebuilt the model entirely.
What makes it even more effective is how it works with Arctic Wolf's concierge experience.
The team brings customer-specific context directly into the platform so every AI-driven
decision reflects your environment instead of generic assumptions.
The automation frees your concierge security team to focus on higher value strategy and
proactive risk reductions while the agents handle the grind.
If you want to see what trustworthy, production-ready AI and security operations actually looks
like go to arctic wolf.com slash hacked.
Never feel like cyber threats are evolving faster than anyone can keep up?
Last year, 2025 was nothing short of a record-breaking year for major breaches,
from sophisticated ransomware operators to AI-enabled attacks that turn defenses on their head.
Organizations around the world saw headlines they never expected and cybersecurity teams
were tested like never before, but here's the thing.
These incidents aren't just news headlines.
They're learning opportunities.
And that's why Arctic Wolf is hosting a live webinar on February 5th, diving to the most impactful breaches of 2025.
Their field CTO and security leaders are going to unpack not just what happened, but why these attacks succeeded.
And most importantly, what businesses can do to fortify their defenses for it's too late.
You're going to walk away with real insights into how threat actors are evolving, how defenders are responding,
and what strategies can help you stay ahead of the next big breach.
It's not fearmongering.
It's practical, actionable, intelligence from experts in the trenches.
Register now at arcticwolf.com slash hacked.
Yeah, so the thing I want to talk about is supply chain attacks into software libraries
and packages that people are using in the development of their software applications.
Okay.
Does that make sense?
I think so.
So when people are developing software, they're using these pre-existing packages,
like these like third-party libraries.
Correct.
And it's a supply chain attack.
into that thing.
Correct.
So like,
take me through it.
If you're using like Python,
like a big part of using Python
is like it has all these packages
you can install.
The Python package index and PIP
is like a way that lets you grab
chunks of source code
that like are containerized
to do a specific thing
that your application needs to do.
So instead of you writing all that code,
you can just grab these packages
to facilitate it.
Same thing with like Node.
There's a package
manager there called Node Package Manager MPM or PNPM if you're using a better one.
But essentially there's like boatloads of open source source code that gets included in tons of production systems.
It's something like 80% of most like contemporarily developed program systems use like 80% of this code is coming from packages that they're including.
Okay.
So it's become a target.
It's become an attack vector.
So a lot of nation states, especially North Korea, have been looking at and compromising
or publishing their own packages for very basic things that they know a lot of users are going to want to do.
And inside of that code package is malware, a remote access Trojan, crypto thief, username credential, grabbers,
Like you name it.
Okay.
So just so I understand here, when we talk about, so the malware comes,
someone has hacked one of these third party packages.
Just so I understand, is the goal to hack the developer that's using it or is the goal
to get the compromise into the software that the developer is shipping out into the general
public?
Correct.
The second one.
The latter.
Oh, that's worse.
That's the worst one.
I ordered them in escalating worseness.
You can do it both ways, but typically it is the,
the latter way.
The bigger impact is to have it in the latter.
Okay.
So this just happened again,
which is what threw this into my eyes.
So in just this month, actually,
a package RAND user agent was compromised
and including in it was a remote access Trojan.
So like a full-blown Trojan
to get remote access to people's computers
was embedded in specific versions of this.
package.
Okay.
And just so I understand something like
RAND user agent, like broadly speaking,
what is that?
So when you do a web request to a
web server comes in with a user agent
and essentially this
package, I think, allowed
applications to generate
random user agent keys.
So like when you
submit a request or like a web server
retrieves a quest, it also tags it as
what the user agent token is.
and usually it's like Chrome, Mac,
like you've seen them before, guaranteed.
So this was a package to facilitate doing that.
Got it.
And I think the package had been deprecated,
so the lead developer that had built it
had just kind of walked away from it.
It wasn't maintaining it,
and somebody grabbed the maintenance of it,
and then immediately stuffed like a rat in it,
a remote access Trojan.
Sure.
So.
I'm slacking you.
an XKCD comic that this reminds me of, which is, it's just one illustration,
and it's this mountain of like Lego brick-shaped things.
And it says all modern digital infrastructure.
And then the whole thing is being held up by this narrow, skinny little brick labeled
a project, some random person in Nebraska has been thanklessly maintaining since 2003.
And I'm reminded of that in this.
That is modern software development, open source software dev and like package development
and library development is tons of that.
It's boatloads of people tirelessly building a specific library that allows for specific things.
And then you get GitHub stars for it.
And that's the social media clout is like, oh, my project has a bunch of stars.
But it also means that I spend 60 hours a week maintaining this thing for free so that all of these companies can utilize it for profit.
Oh, I have so many questions.
That's great.
But that's the like, oh man, I'm really reticent to connect this back to the first story.
But like what a positive use of the gamification of the desire for clout.
Like in a positive way.
Like cloud doesn't even really feel like it captures it.
It's like you genuinely want to contribute to something positive in the world and help people make things.
Yes.
Okay.
So these third party packages, this scaffolding for modern technology,
becoming a new attack vector for getting people into it.
And for getting into people's systems
and then getting disseminated out into the world.
What, like, without just rethinking how software development happens,
which seems like it's quite dependent on these things,
how do you, like, what then is the answer?
Like, is it just be really, really careful with all of your dependencies?
Like, is there an answer to this or is it more just a warning?
I think, like, if you're a big, like, if you're a commercial enterprise,
it makes commercial products, you're probably pinning certain versions of it.
So you're only, maybe you get like this package or like probably a bunch of packages
and you're like taking them at a specific version like 2.1.8 or something.
You've done a code review of it to make sure.
In an ideal sense, you've done a code review to make sure there's no remote access
Trojan embedded in it.
and then you're kind of consistently from that moment on maintaining your own fork of that package.
So fork is like a term that means like you grab the source code at that point and you take ownership of it for yourself.
So now that it's integrated into your system, you're going to be the one that maintains that packages source code.
Oh, I see.
You take a little bit of accountability for the dependency in a word way.
Yeah, instead of just like because the other thing.
thing is, like, if your system depends on, you know, some package, and the package maintainer
decides to change the entire programming interface for it, and you just have it auto-updating
in your build script, it could just shatter your system. So good code, like good CICD code,
and good maintenance and security protocol would be to probably, like, take a snapshot of
the code base from that library, review it.
and then consistently maintain it for yourselves.
But again, that's a lot more work
than just letting the guy from Nebraska toil over it.
Keep support that one Lego brick.
Your question's interesting
because it's like one of the most notable
of this style of attack actually happened.
It was one of the first ones in 2018.
And there was a widely used node package
called Eventstream,
approximately 2 million downloads per week.
So that shows you the scale of development
activity that was being used on it.
And the main maintainer
and the person that developed it just got burnt
out on it and just wanted out.
So they were like, you know what,
I'm going to deprecate it, pass it off
if anybody else wants to take ownership and publishing
rights to it and wants to take over the
responsibility of developing and maintaining
this library. And they
transferred it to a user
called Right9 Control
who was like, you know what, I'll take it.
And the first thing they did
was embed a crypto mining
like a crypto theft like Trojan into it or like malware into it.
Sure.
So it was a lot,
it was all just to get down to one crypto.
It was to get crypto mining into other people's systems or to break into a crypto wallet?
Break into crypto wallet.
So then here's the thing,
2018.
He's bad,
but that's fascinating.
2018,
he was selective.
He only wanted,
or they,
I should say,
they only wanted wallets that had
more than 100 bitcoins in them.
Yep, okay, big fish.
But 2018, so I don't know what the value was then, let's call it 20,000.
So that's like still a lot of money.
Where today 100 bitcoins is like $10 million.
Is that right?
Jesus.
100 Bitcoin.
No.
Oh, maybe.
Yeah.
I think it's 100K.
Yeah.
140K.
Or I guess CAD, yeah.
Yeah, yeah.
100,000 U.S.
So yeah, it's a.
Jesus.
Anyway, so the, yeah, it was like the first thing.
It was like the next iteration of the library that came out had this, like,
crypto thieving malware in it.
And it would just like any computer that it was installed on, it would scan for a crypto wallet,
identify whether it had more than 100 bitcoins, steal the keys to the wallet, and, like,
send it back to home.
We were, we've talked about the different, like, AI development environments on this show before.
And I don't know, you and I have just talked a lot about cursor.
but there was one of these with cursor too.
There's like a commonly used package for cursor that I guess was treated as one of these
little avenues for a compromise.
I think that was to steal API creds, if I'm not mistaken.
I'd have to have to look that one up.
It wasn't as big and as impactful.
I think the biggest one ever was in 2021.
1.
UA Parcer.js.
So like a JavaScript parser.
Parcars user agent strings.
Same kind of style of thing.
So the user agent coming in from the server,
this was an automated thing that would grab the string
and parse it into its components.
So you could tell whether it was an OSX or like what its OS was,
what the agent was, what version the agent was.
And they saw tainted versions of it starting in 2021.
One. Some of them actually went as far as to include a .exe in them, which was an actual
crypto miner that would run on the computer of the person that had installed the package.
So again, cryptocurrency at the heart of the theft.
And again, I think of the person in Nebraska, it's like maintainers are human beings.
Like people get burnt out.
People that are maintaining long-term projects get stressed.
You don't know what's happening in people's lives.
and a person that's like tirelessly defending and maintaining something is like can be as targeted by a thing like social engineering as anybody else.
It's easy when these projects are depended on by so many people to kind of think of them as like, well, it's the wisdom of the crowd.
I'm sure someone's on this.
And it's like that's not necessarily a reasonable conclusion.
Well, it is such a big part of the community, like the development community.
There's so much leverage.
Like the value of some of these languages and platforms and frameworks
comes down to the accessibility of free tools for them.
If you think about Python,
Python's become like the machine learning AI like baby.
And it's because it's just an amazing set of libraries
that are just given out for free to use in that space.
So it becomes so much easier.
Like if you imagine having to rewrite something like,
pie torch and pie chants from like scratch just to utilize these things it would take forever.
So like to facilitate community growth and innovation, a lot of these packages do that.
Like you can build an app really quickly because if you think of an app like a recipe, you know,
if you had to had to make eggs.
Yeah, if you had to mill flour every time you wanted to make bread, the process is a lot more complicated,
but there's some downstairs.
Totally.
Exactly.
Yeah, yeah, yeah.
So that's the thing is, like, a lot of these packages are just there.
And what you're seeing now is, like, because it is such a stress, like, I would never,
I would love to be a contributor and actually might be becoming a contributor to an open source package
because the open source app I was building some guys from San Francisco released it already.
So, like, why would I?
Sure.
Why would I rush to do it?
But anyway, what you're seeing now is, like, major companies.
like meta, Microsoft, like Visual Studio Code is a Microsoft maintained product.
Like the React framework for like Node and web development is like a meta-maintained framework.
And it's like a lot of these massive enterprises now are actually the ones releasing and maintaining a lot of the bigger packages.
This is good.
Yeah, I mean, there's just something to be said for like,
redundancy.
One person can burn out and can slip up, but hopefully, I mean,
what large organization could get compromised in a hack?
That's never happened.
To talk about size and scale, like UA. Parcer, JS,
when that one got compromised injected with malware and crypto miners,
it was doing 7 million weekly downloads.
So it's like 7 million developers essentially download
in that package.
And actually the most recent one that I mentioned, the other user agent one, they actually
didn't release the name of it.
It kind of got found out because they were ran user agent because it was in so many
production systems that they wanted to give the developers time to remove the remote
access Trojan before anybody really found out what it was.
Okay, so what have we learned here?
Open source is cool.
And useful and kind of a gift that we give each other.
But it's also, there's potential for vulnerabilities there.
Yeah.
As like a, it seems like a lot of the big ones are nation state style, like North Korea's
kind of cyber crime department, for lack of better terms, is big on using this style of attack.
And like we've talked about it on the show before.
Because it just, it gives them, it opens a lot of doors.
at once. You know, you put a, you put a piece of malware in one place and then somebody else
is distributing that for you. All of a sudden, you've got malware all over the place.
Yeah, sure. You wouldn't believe who's baking cookies with this flour that we put on all the
shelves. It would shock you. Yeah. Yeah, right. No, it's, it's shrewd. And it's like,
stacked sort of like, I'm trying to think of like the word to use for this. It's like a transitive
dependency where like you got it into a thing that got it into a thing that got it into a thing and
you're like I didn't even know where this was going to end up and now this vulnerability in this one
package is inside of another thing. It's inside of another thing that's inside of the White House.
Totally. Yeah. Fun is the wrong word but there would probably be something kind of neat about
being like you wouldn't believe where it showed up today. If you were like for fun activities,
if you were the person that was like had done this, having it.
Having it like its callbacks, like when it calls home to tell you where it is, mapping that and getting to watch the like 3D connected state diagram of like as it spreads and see it would be like fascinating to watch.
But no, it's, I think that this is going to be this is going to be a place where I think AI is going to become really successful in both ways.
Because I think the more people that are writing code and developing stuff without actually.
knowing what they're doing is going to increase the attack vector.
But I think that you're going to see platforms and production environments and IDs get really
intense with AI code reviews, looking for potential vulnerabilities, looking for fingerprints of
like anything, like GitHub at some point will automatically fingerprint whether there's any
kind of sus code in your stuff.
I imagine they're already probably building that.
We saw that stuff at DefCon where there was that massive multi-organization challenge going on,
having like AIs find vulnerabilities in code and then patch them.
And I think you'll see some of that same implementation come to some of these like code repositories, code submission,
CICD pipelines, things like that.
I'm wondering how this is going to sit with people, the darkest story we've maybe ever told in the most like,
just so you know there's a fascinating thing going on with these dependent code packages.
Normally we like to find a nice middle ground between the tech and the human and
boy, did there? Is there just a chasm there today?
I don't know. To me, the like code one is...
I love it.
The first story, 7644 pretty dark.
It's pretty dark. Learned a lot of new terms that I didn't care to know about.
Gore butcher.
Gore butcher.
Code dependency, supply chain attacks.
fascinating to me.
I agree.
It's like it's the tools that you use.
These are like the tools used to create modern tools.
And it's like, well, what if the hammer was actually evil?
It's like, well, that's interesting.
Yeah, exactly.
Yeah.
And like the thing is too is like we talked to you talked about and you brought it up like like burnout of project maintainers.
And like it's a lot of thankless work.
And like like you spend.
it's like the meme like deal like you give me 1500 hours a year of free work I give you angry comments in GitHub issues and it's like that's what it is like somebody complaining about how the code's broken in a specific way and it's like that's your that's your payback for it and and some stars some like thumbs ups and to me that's the thing it's like as these maintainers burn out I think I think
as they transition away from them and hand over the keys to the project to other people
to take over the thankless role of pushing the stone up the hill,
those people could be the North Korean Cybercrown Division.
And especially if it's a large enough package that's in so many things.
It's like one piece of local, like one package that would be used on local applications
that like if it was big enough could push malware.
remote access Trojans to millions of PCs.
And it's like that's such an interesting supply chain attack that could have such a big
output.
I can see why somebody like North Korea has prioritized it.
This is a goofy note to end on.
I love sci-fi.
And there's a trope in sci-fi of like the imagined sci-fi world where they still have
the futuristic technology, but they're so far ahead of it that they've forgotten how it was
created.
Like Warhammer 40K.
That's a big thing in that.
lore universe of like we have these dreadnots.
Why don't you have new ones?
Because we forgot how to make them long ago because we're too busy murdering each other.
And it's fascinating to imagine a world where there's all of these software dependencies
that were developed by people at some point in the past and hand it off and hand it off and
you have people using them that don't entirely maybe know what's in them and how they work
anymore at this stage because of how they learn to develop software in the modern age.
It's like it's an interesting world to imagine where we're building things out of
parts we don't totally understand.
Oh, yeah.
Well, like the, and some of those packages are so small.
Like, like some of the most common node packages are like basic functions that just
don't exist in the base language.
So somebody writes one function that does something, like checks if an array is, like,
has some specific constraint.
And that package gets used like 13 million times because instead of,
instead of people like rewriting the one function that does it, they just include the
package because it's like somebody else does it. And it's like if those, you know, things like
that, like, and that's some of the, some of the packages that North Korea was building were things
like that, like things that are just easy use. If you're kind of, I don't want to say too lazy,
but like you didn't want to rewrite work that had already been done for you. You didn't want to
mill your own flower. Yeah, you didn't want a million your own flower. It's extremely
natural and reasonable to want to use those preexisting tools. And it's super obvious to go
after them if you're that kind of an Asian state actor.
Totally. And like the, yeah,
we could talk about vibe coding and how that's going to affect this,
but there's no point. I think everybody kind of understands.
Yeah, we all got a gist.
Well, everybody, I hope you enjoyed this conversation
about code dependency supply chain attacks and internet death cults.
We sure had fun.
I'm going to go lay on the couch for 40 minutes.
Go stare at a wall.
As always, this was,
It was a pleasure. Thank you all for listening, and we'll catch you in the next one. Take care.
