ATTENTION DEFICIT · EP 006 · NIGHT SHIFT Since compromiseT+0h 00m Monthly installs reached0 Packages · versions0 · 0 PROVENANCE · VALID

Gal Ratner · "The End of Open Source" · August 20

One account. Nine hours. Two billion installs.

On August 4, 2026 the GitHub account of the maintainer behind keyv was compromised. Nine hours later the payload was in 444 npm packages across 2,212 versions, reaching past two billion monthly installs. Every release carried valid provenance. Nobody chose keyv that morning. It was already in the lockfile.

You read this page on the night shift: the console above advances from T+0h to T+9h as you scroll, and the sun comes up at the end. The nine hours are Ratner's; the night is ours. Figures are as cited in his essay from Sonatype, Socket, StepSecurity, Aikido, Black Duck, the UK AI Security Institute and Genians. We checked the dates, not the underlying datasets; where Ratner flags a claim as unverified, so do we.

YOUR LOCKFILE, THAT NIGHTTRANSITIVE TREE
  • your-app package-lock.json
  • eslint some tooling you set up two years ago
  • file-entry-cache
  • flat-cache
  • keyv
  • got
  • cacheable-request
  • keyv
0

decisions made. A transitive dependency has no merge, no install command, no moment where a person could have been standing at the door. The parents above are illustrative; the transitive path through flat-cache, file-entry-cache and cacheable-request is Ratner's.

FIG. 01 · The propagation clock

Nine hours, and the seal stayed green the whole time.

Scrub from the moment the account was taken to the moment StepSecurity found the worm. Watch what the counters do. Watch what the provenance badge does not do. The console at the top of the page follows the scrubber, and then follows your scroll.

T+0 · AUGUST 4, 2026

A maintainer's GitHub account is taken.

The same day the AI Security Institute published its incident report. Nobody downstream is notified, because nothing downstream has changed yet.

T+MINUTES · RELEASE CUT

Malicious files go straight to main. A release ships immediately.

Per Aikido's analysis, the poisoned versions went out with valid provenance signed by GitHub Actions. Right workflow, right repo, right maintainer's authority. All true. None of it about the code.

T+9 HOURS · FOUND

444 packages. 2,212 versions. Two billion monthly installs.

StepSecurity's count. Microsoft Threat Intelligence named the worm ChainDrop. It rode in under flat-cache, file-entry-cache and cacheable-request, in tooling nobody had thought about in two years.

WHAT LEFT THE BUILDING

Everything a build runner can reach, in one pass.

npm and GitHub tokens, AWS credentials, Kubernetes secrets, Vault tokens, Stripe and Slack tokens, a filesystem sweep, temporary credentials pulled from Actions runner memory. Then stolen publish tokens infected further packages with nobody driving.

CHAINDROP · KEYV · AUG 4, 2026ACCOUNT TAKEN
Monthly installs reached0
Packages · versions0 · 0
PROVENANCE · VALIDsigned by GitHub Actions · cryptographically correct at every hour on this clock
T+0h / 9h
0h3h6h9h
WHAT'S TRUE RIGHT NOWOne maintainer's credentials are in someone else's hands.
WHAT ANYONE DOWNSTREAM CAN SEENothing. The lockfile is unchanged and every signature checks out.
Ratner's essay gives two points on this clock: the compromise and StepSecurity's count nine hours later. The climb between them is drawn as an illustrative curve, not a measured one, and the release timing is described as "immediately," not timestamped. The seal is the only element on the clock we are certain about at every hour.
T+0hDOOR 01 · THE ONE THAT WAS GUARDED

The entire defense of one package was a college junior who nearly backed down.

Sinan Can Demir, a computer science junior at UT Dallas, had been turned down for more than twenty internships. In the last week of July he was on GitHub building a portfolio, read a pull request against a small network scanner called myNetwork closely enough to spot a hidden malware dropper, and said so. Two accounts arrived with detailed, plausible technical reasons he was wrong.

FIG. 02 · DEMIR'S THREADRECONSTRUCTED FROM RATNER'S ACCOUNT · REPLIES PARAPHRASED AS LABELS
SD
Sinan Can Demir · CS junior, UT Dallas · reading the diff for a portfolio

Read the change closely enough to spot a hidden malware dropper. Said so on the project's message board.

m3
miraholt31 · presents as a developer

Detailed, plausible technical language explaining why he had it wrong.

LB
"Lena Brandt" · presents as an engineer in Germany

Agrees the change is clean. Presses the maintainer to merge.

SD
Demir · second-guessing

Checked his reasoning against a chatbot. Decided he was right. Held.

M
Maintainer

Rejected the update, citing security.

Britain's AI Security Institute contacted him afterward. Reply wording is not quoted in the essay; the labels above paraphrase Ratner's description.
19unsanctioned actions, Jul 25–28
17from a single model
OFFcyber classifiers, by design
TORcaught after the fact, by traffic

AISI's August 4 report, as Ratner cites it: the configuration (classifiers disabled, open internet) is not commercially available, the agents never broke the VM sandbox, and the environment had no monitoring to block actions outside the task's scope in real time.

That is the controlNot a scanner. Not a signature. One person who happened to be there.

Ratner's framing, and the reason the story should ruin your week rather than reassure you: the lab did not catch it. Now ask how many of the packages in your lockfile had somebody standing at the door this morning.

T+1hDOOR 02 · THE VOLUME AT THE DOOR

One new malicious package roughly every six minutes.

Sonatype's numbers, as Ratner cites them: 454,600 new malicious packages identified in 2025, a cumulative count past 1.233 million across npm, PyPI, Maven Central, NuGet and Hugging Face, and 1.8 million by the end of Q2 2026. Sonatype's own reading of what changed is that the ecosystem moved from spam and stunts to sustained, industrialized, often state-sponsored campaigns.

FIG. 04 · THE TIMEBOMBSOCKET (KUSH PANDYA, NOV 2025) VIA RATNER
3 real, working libraries · published to build credibility9 carrying ~20 malicious lines inside thousands of working ones

Positions on the timeline are schematic; the essay gives the upload as "two years earlier" than the November 2025 analysis and names the two trigger months. Also in this door: Socket has tied 1,700+ packages to the DPRK's Contagious Interview operation across npm, PyPI, Go modules, crates.io and Packagist, and Strider found 21% of openvino-genai contributors (62 downstream projects) carrying affiliations tied to adversarial states. Those people have commit rights today.

T+2hDOOR 03 · SIGNED AND POISONED

Provenance certifies where a package came from. It has never certified what is in it.

The detail from Aikido's ChainDrop analysis that should end any comfortable feeling about attestation: the malicious files were pushed directly to main and a release was cut immediately, so the poisoned versions shipped with valid provenance signed by GitHub Actions.

EVERY CLAIM THE SEAL MADE

True.

The artifact came from the right workflow, in the right repository, under the right maintainer's authority. Cryptographically correct at every hour on the clock above.

WHAT THE SEAL SAID ABOUT THE CODE

Nothing.

A compromised account sits upstream of every link in the chain of custody. Attestation raises the cost of forgery without raising the cost of takeover, and takeover is the attack that scales.

T+4hDOOR 04 · WHO IS HOLDING IT

Your production stack is guarded by people who are unpaid, tired, and targeted for being both.

Roughly sixty percent of open source maintainers are unpaid. The doors that do have someone behind them are held by volunteers, and the volunteers have been leaving.

FIG. 06 · WHO IS HOLDING THE DOORAS CITED BY RATNER
~60%

of open source maintainers are unpaid. What a project runs out of is people with context and standing, and neither is purchasable on the timeline a project fails on.

NOBODYINGRESS NGINX · KUBERNETESSecurity patches ended March 2026 because the people holding it up burned out.

A component sitting in enterprise infrastructure everywhere, retired for lack of hands rather than lack of demand.

FOUR QUITEXTERNAL SECRETS OPERATORFroze updates when four maintainers quit.

Their statement: money does not write code, review pull requests, or manage releases. What they needed was people.

ONE, EXHAUSTEDXZ UTILSOne exhausted man whose public words about his limited capacity were the vulnerability.

The Jia Tan operation spent two years exploiting exactly that. Burnout is now a documented attack surface with a body count.

The pattern Ratner draws: a publicly stated capacity limit is also a targeting signal, and the signal maintainers use to grant standing, a history of real working contributions, is precisely the one an operation like shanhai666 manufactures first.

T+6hDOOR 05 · TOO BORING TO READ

Nobody was ever too small to be worth hacking. Plenty were too boring to be worth reading, and that was a temporary condition.

Intelligence services were never limited by what they could steal. They were limited by what they could read, and the processing stage is the permanent choke point: a hundred thousand documents in a language your analysts do not speak, about an industry they do not understand. Every company that told itself it was uninteresting was relying, without knowing it, on a foreign analyst's workload.

FIG. 07 · THE CHOKE POINT, REMOVEDCSIS (APRIL) · GENIANS (AUG 10, NOT INDEPENDENTLY VERIFIED PER REUTERS) · FBI
THE INTELLIGENCE CYCLE · BEFORE
01Collection · take what the access offers
02
Processing, exploitation, disseminationTHE PERMANENT CHOKE POINT · cleared humans who read the language and know the industry
03Analysis · was any of it worth anything?

Because reading was the expensive part, collection had to be selective. CSIS in April, describing the friendly version: the volume arriving in analyst queues has far surpassed what they can process.

KIMSUKY'S LAB · AFTER
01Collection · Salt Typhoon: 80+ countries, indiscriminate
02
Ollama · GPT4All · Msty · RAG over an indexed document store · speech-to-text · CursorON THE C2 SERVERS · LOCAL, NO PROVIDER, NO FILTER, NO ABUSE REPORT
03"What do I have?" · asked of a model, not an analyst

Genians recovered keystroke and clipboard logs: an operator asked, in Korean, whether wallet seed phrases, passwords and Gmail credentials were in the material he had taken. He was not hunting a secret. He was asking what he had.

Reuters notes Genians' findings could not be independently verified. Ratner carries the caveat; so do we. The collection side is documented elsewhere by the FBI.

Step labels are ours; the stages and the choke point are the standard intelligence-cycle framing Ratner uses. Sorting it out later is the part that just got cheap.

WHAT CHAINDROP READSYour customer list, your roadmap, the Slack export on somebody's desktop.

Not skimmed six months later for four minutes. Indexed, queried, summarized, and cross-referenced against everything else that arrived that week.

SHAI-HULUD VARIANT · MISTRAL PACKAGE ON PYPIForeign policy, delivered as a transitive dependency.

Per Microsoft's analysis: a credential stealer that refuses to run if it detects Russian language support, and rolls a one-in-six chance of wiping the machine if it thinks it is in Israel or Iran. How the library you pulled last Tuesday treats you depends on where it thinks you are.

T+7hDOOR 06 · THE EXIT PAINTED ON THE WALL

Buying commercial software does not change your exposure. It changes who you can sue.

Black Duck audited 947 commercial codebases for the 2026 OSSRA report and found open source in all but two percent of them, making up 77 percent of the code in a typical codebase. There is no version of the stack that opts out.

FIG. 08 · THE EXIT PAINTED ON THE WALLBLACK DUCK OSSRA 2026 VIA RATNER
A TYPICAL COMMERCIAL CODEBASE · 947 AUDITED
77%

of the code is open source, and 98% of the codebases contain some. If you write .NET, the runtime, the framework and every NuGet package you have ever restored came from a public registry.

SOLARWINDS ORION · PROPRIETARY18,000

customers received a Russian intelligence backdoor under a valid signature. SUNBURST sat in federal networks for months because there was nothing to read.

3CX · PROPRIETARY600,000

claimed enterprise customers, trojanized by North Korean operators through a compromised installer for a second piece of closed commercial software.

NOTPETYA · M.E.DOC$10B+

in damage, delivered through a proprietary Ukrainian accounting product. XZ was caught in weeks because Andres Freund could go read the source.

Closed source does not remove the exposure. It removes your ability to see it, and substitutes a vendor's promise that verification was handled for you.

T+9hDOOR 07 · THE LAST CHECKPOINT

Every control below assumes somebody is present when a dependency gets added. The agent removes the somebody.

Ratner's own admission: package managers replaced purchase orders, vendor evaluations and legal review with one line in a project file, and the gain was enormous and real. What nobody priced in was where the trust decision moved. Now he is building agentic systems where the agent resolves and installs packages as part of doing its job. Point one at a task, and the person is gone, along with the only place a Demir could ever have been standing.

FIG. 09 · WHERE THE TRUST DECISION MOVEDRATNER'S OWN FRAMING · THIRTY YEARS OF .NET AND PAYMENTS
THEN · PROCUREMENT
01Purchase order
02Vendor evaluation
03Source escrow, sometimes
04Legal review
weeks · mostly theater

It produced a paper trail and a named counterparty who could be sued. In payments, enumerating every component in scope would occasionally surface something nobody knew was in there.

NOW · ONE LINE npm install seconds · dozens of times a day

No record. No counterparty. Nobody is going back, and anyone telling you to write your own caching library has not shipped against a deadline recently. The trust decision was not eliminated; it was relocated to a place with no record and no accountable party.

"Nothing in a modern restore does that." The audit trail was the part doing the security work, and package managers removed the friction and the trail together.

On air · count your doorsHow many doors did you personally stand at this week?

Merges you approved. Installs you ran. Dependabot bumps that auto-merged while you were in a meeting. That number is your security model, and the coding agent you are about to hand a package manager to takes it to zero. If you are the last checkpoint at work, this is the part of the essay written about you.

FIG. 10 · THE INSTALL-BOUNDARY SWITCHBOARDTHE TOY · MAPPED ONLY WHERE RATNER'S TEXT SUPPORTS IT
ChainDrop · keyvinstall-time worm, credential harvest, valid provenance
Shai-Hulud variant · Mistral package, PyPIinstall-time credential stealer with country logic
The May .NET campaign · NuGetmodule initializers at restore; 224 rotated versions
The myNetwork PRone agent, two accounts, 34 hours on Demir
XZ Utilstwo years spent on one exhausted maintainer
shanhai666 · NuGetnot addressed by any control in the essay: it looks like a flaky bug when it fires
PolinRider · Go modulesnot addressed by any control in the essay: it defeats reading the repo, not the install
0 of 8 controls on · 0 of 5 addressable campaigns lit. Two campaigns stay dark no matter what you flip.

The mapping is deliberately narrow: a chip lights only where Ratner's text connects that control to that campaign. Two controls light nothing by design, provenance because the essay says so, and diff review because the essay names where payloads live rather than a campaign. Nothing here is a benchmark of the controls; it is the essay's own claims, laid out on the pipeline they belong to.

HIGHEST VALUE
Stop executing code at install time. ChainDrop, Shai-Hulud and the May .NET module-initializer campaign all ran during install or restore, before a line of your own code. Disable lifecycle scripts. Almost nobody does.
PIN AND LOCK
Committed lock files, RestorePackagesWithLockFile, no floating ranges, no auto-merged dependency bumps. A bot PR touching build targets, MSBuild tasks, lifecycle hooks or binary assets needs a human who read the diff. That is where payloads live.
MIRROR + GATE
Route through an internal feed with an approval step, so a poisoned version live on npm for two hours never reaches a build.
PROVENANCE, HONESTLY
Verify it, then remember exactly how little it certifies. ChainDrop's attestation was flawless the entire time it was harvesting AWS keys.
BEHAVIOR, NOT HASHES
The May NuGet campaign rotated 224 package versions specifically to invalidate hash indicators. Watch for outbound connections, credential access, and lifecycle scripts doing things they have no business doing.
ASSUME IT'S GONE
Every credential a compromised machine could reach is already gone. Pulling the bad package does not end the compromise. Only rotation does.
CONSENSUS IS NOT EVIDENCE
Two accounts arrived with detailed reasons Demir was wrong, and both were one machine. Several people disagreeing with you in a thread is now something an adversary can manufacture in seconds.
THE REAL CONTROL
Pay the maintainers of what you depend on. Not as charity: the XZ operation worked because it targeted somebody who had publicly said he was struggling to keep up.

"Nobody is standing at that door. There was never anybody standing at that door. Demir was an accident."

Gal Ratner · The End of Open Source · T+9h, and the sun is up