Transcription
Everything is back door. Yes, I mean it. No computing system is immune. If you think that not using Windows means you're safe, that is not true. If you think that timely updates protect your devices from bad actors, uh, unfortunately, I have bad news for you. If you think that not using hardware from unknown Chinese vendors guarantees absence of malicious firmware code, again, I'm afraid I will disappoint you. If you think that TLS encryption of your HTTP traffic hides your secrets, yeah, you know, or maybe maybe you even think that if you are not a criminal or a political activist, then you have nothing to worry about. You're just an engineer and you have nothing critical or life-threatening on your laptop. I'm sorry to say, you're wrong. We are in a state of IT security war and this is our world for at least the next decades. If you doubt what I'm saying, just continue watching. And if you agree with my statement and just not sure what to do about it and how to live in the state of IT security war, I have something to say as well. I'm not a security expert, but through my 20 plus years of IT experience, I've seen some. I'm not going to sell you a magic pill because it doesn't exist. But I want you to pay attention because we all are in the same boat.
First, a confession. In my early career, I worked for shady companies. Back in my country of origin, I was on a payroll for the guys that we could call now cyber criminals. I was living and breathing the industry of not completely legal advertisement for many years. I thought that what was going on there, the work practices, very special ethics and so on is the norm. That is why I have at least some authority to share my opinion on the current state of events in IT security.
Many of you probably read the news about a JavaScript worm that infects npm packages stealing cloud credentials along the way. But if you were on an internet detox for too long, here is a story. On September 15th, 2025, Daniel Pereira, a software engineer from Brazil, writes a post on LinkedIn that almost gets unnoticed. There is a malware spreading live in npm. As you read this, npm is a JavaScript package repository with over 3 million packages that are used both for backend and front-end applications. On npm, you can find everything. For example, a package that literally ships a single function which checks if a number is even. You think it's a joke? Think again. Almost 200,000 downloads weekly. Package published 8 years ago. Or here is a package called debug which is in fact not much more than a glorified print statement, almost 400 million weekly downloads. And of course, from npm, people install big popular frameworks like React or Angular, frameworks that power countless front-end applications. It's probably not so difficult to hide just about anything in the code of a language that treats obfuscation as a part of a development workflow, a language that can convert any program into these six characters. And so this is what happened.
First, the bad actor got hands to npm publishing credentials by targeting a group of npm package maintainers with phishing emails. I don't have the numbers, but my feeling is that phishing is the delivery vehicle for most software backdoors. Okay, so the stolen npm credentials were used to implant the actual backdoor into a bunch of npm packages. The backdoor would scan your system for interesting credentials and send them back home using GitHub Actions, a continuous integration system. But I think that Shy Hulk, this is how you can search for this backdoor, got so much media interest not because it was sneaking on secrets, but because, as the name suggests, it was a worm. By definition, a worm is a malicious program that replicates itself from one device to another. This is how it works. You npm install one of the infected packages, and the package manager calls a 4 megabyte post-install script, obfuscated, of course. While npm post-install scripts are a legitimate way to install platform-specific binaries, for example, if you ask me, it's a horrible, horrible idea to let package managers execute code without explicit approval from a user. By the way, it got even further than that in the Python packaging ecosystem. There, you can have something running on your machine without you knowing when pip just searches for dependencies resolution. Now, what if I tell you that pyproject.toml was in part aiming to fix one of the worst non-persistent security backdoors in Python packaging infrastructure, a backdoor in fact so horrible you wouldn't even notice when your machine, a laptop, a CI/CD server, or maybe even your container image deployed to production is exploited? More on that in my other video if you are interested. So npm runs the malicious post-install script which, as I said before, collects credentials, and if the worm was lucky to land on an npm package developer's machine, it uses npm publishing credentials to inject itself into even more packages. This, as you can imagine, led to a snowballing effect. Back to Daniel Pereira, who decided to stop the avalanche. The link in the post in which he tried to warn the community not to install infected npm packages went almost invisible. Daniel then tried to reach out to GitHub to ask for their intrusion. But taking action on such events where sensitive information is at stake is not easy. When companies specializing on supply chain attacks started their investigations, among infected npm packages were a dozen of packages that belong to CrowdStrike. Yes, that CrowdStrike which claims they stop breaches. God definitely has a good sense of humor. Eventually, infected npm packages were unpublished. Malicious CI workflows and GitHub repositories used to publish stolen credentials were taken down.
You might now think that such backdoors are only possible with dynamic programming languages which allow you to run code without any proper control. Let me now read you from the Cargo book, a document for Rust package maintainers. "Placing a file named build.rs in the root of a package will cause Cargo to compile that script and execute it just before building the package." Here you go. The bomb is there, just waiting to be activated. "It's a secret. It's a secret weapon." Stay humble. Or maybe you hope that giving up all the programming languages specific package management systems and relying just on your distribution will protect you from backdoors, because sure, there's more control over what's being published there. At least because you cannot just go and upload something without approval and have people happily installing your creation on their machines. But, but, but, but remember the XZ backdoor. It took years of patient and careful work and very sophisticated programming to plant and spread it. So unlike Shy Hulk, by the way, infected XZ utils packages landed in Debian, Fedora, openSUSE, and the most advanced penetration testing distribution Kali Linux. Just the sheer luck and incredible attention to detail of Andres Freund, an engineer working on PostgreSQL at Microsoft, saved us from the real consequences of this brilliant attack. If it would succeed, the great cardinals behind this operation would get a remote root-level access to virtually any Linux system in the wild.
Now, you could think that security-focused open-source operating systems like OpenBSD, that is often used for network appliances, are by definition better protected from backdoors. But aren't they also a likely and very precious target for attacks? In 2010, Theo de Raadt, the leader of the OpenBSD project, wrote on an OpenBSD tech mailing list, "I have received a mail regarding the early development of the OpenBSD IPsec stack. It is alleged that some ex-developers and the company they worked for accepted US government money to put backdoors into our network stack, in particular the IPSec stack around 2000-2001." For those who don't know, IPsec is a very established VPN protocol that was and still being used by many big enterprises. And although the real evidence of the IPsec backdoor, like a certain commit with malicious code, was never found in OpenBSD repositories, it made me think, what if we know about this particular backdooring attempt only because it failed? What about all the other attempts which I'm sure did happen and may be happening as we speak. This story also makes it clear that backdoors are not just the tool used by cyber criminals to hunt for your cloud credentials or steal your crypto wallets, because the first customers of the first backdoors were governments, and yes, just like these days, they were trying to break into encryption mechanisms. Operation Rubicon was a joint secret program of intelligence services from West Germany and the United States in order to get access to encrypted communication between governments of more than a half of all nation-states in the world. In 1970, these two spy agencies secretly bought a company from Switzerland, a company called Crypto AG, which sold devices like this. This is CX52, a mechanical device of the size of an iPad mini. To operate it, first you get the cipher for today and set it by rotating these six wheels in front. Then you select a letter by rotating the dial on the left. Pull the crank and the dial, obeying now a complex mechanical logic, will point to an encrypted version of your letter. Letter by letter, you prepare an uncoded version of your message which is then transmitted using Morse code over a radio frequency. The receiver would decrypt the message using that same agreed beforehand daily cipher, symmetric encryption. There was a more advanced version of this device where instead of setting up the daily cipher by rotating the six wheels, you would use a tape produced by a cipher generator. And these cipher generators, basically random number generators, were most likely the target of Crypto AG's shadow investors. So that the random numbers became not so random.
If you think that tapping into encrypted communications could be excused by the needs of the Cold War and are a thing of the past, let me remind you of this guy. And for an even more recent reference, here is a fragment of an interview with Pavel Durov, the founder of Telegram, a messenger platform with more than 1 billion active users. "You know, there's this second part which was probably more alarming. There in the US, we got too much attention from the FBI, the security agencies wherever we came to the US. So to give you an example, last time I was in the US, I brought an engineer that is working for Telegram, and there was an attempt to secretly hire my engineer behind my back by cybersecurity officers or agents, wherever they are called." "The US government should hire your engineer?" "That's my understanding. That's what he told me." "To write code for them or to break into Telegram?" "They were curious to learn which open-source libraries are integrated to the Telegram's app, you know, on the client side, and they were trying to persuade him to use certain open-source tools that he would then integrate into the Telegram's code that, in my understanding, would serve as backdoors. You know what's interesting? In the US, you have a process that allows the government to actually force any engineer in any tech company to implement a backdoor and not tell anyone about it with using this process called the gag order. And there are certain legal procedures." "Not tell his own employer about it?" "And not, yes, exactly. If you tell your own boss, you can end up in jail. Like, gag order." "This actually, yeah, this is something it's on Wikipedia." "Yeah, big tech, and especially social media companies are of course targeted by intelligence companies because they know too much. But those very companies are also not thinking twice if they can backdoor you to improve their competitive position."
In 2016, Mark Zuckerberg was worried about the quick growth of Snapchat, an Instagram competitor with a bunch of innovative features. In a leaked email, Mark wrote to the Facebook's vice president of the growth team that "it seems important to figure out a new way to get reliable analytics from them about Snapchat." That is, as a result, this person Tuckerberg wrote to Javier Olivan, "Kickstarted a new shady project code-named Ghostbusters." This project used some of the best engineering talents from Facebook to implement a man-in-the-middle backdoor in a VPN service that the company recently acquired. A VPN client installed on an Android or iOS device would deploy Facebook versions of SSL root certificates. This basically allowed to intercept and decrypt all the SSL traffic project Ghostbusters was interested in. First, it was analytics sent by the Snapchat app to Snapchat server. Then, analytics from YouTube and Amazon. What's more, an investigation revealed that Facebook had been secretly paying teenagers to install Facebook-owned VPN service on their phones. If you ask me, this is way more disgusting than stealing cloud credentials from programmers.
Development of backdoors and spyware is a huge market. And if you think that companies selling such software are hiding on the darknet, go to your preferred search engine and type in NSO Group. I'm telling you with a degree of authority that people working on software like this are engineers just like you. They go to the office, drink coffee from the same type of coffee machine. Most of the time they are lazy, but they are experts in what they do and they always try to stay up-to-date and learn. They probably also have daily meetings and sprint reviews, by the way, just like you. And yes, they do too use LLMs. In another recent attack targeted specifically at developers, malware used locally installed AI agents to harvest credentials. But yeah, of course, AI agents are the future. Let's give a nondeterministic black box a way to execute commands and modify a file system. What can go wrong?
I started with a claim that everything is backdoored. Yes, it's not just about software. Obviously, there is a long, long track record of backdoors in home routers. But we now know that Snowden's former employer NSA backdoored Juniper devices, routers, and firewall appliances, which are the backbone of data center networking around the globe. NSA did not reinvent the wheel but executed on what they were allegedly successfully doing with crypto: tempered the random number generator. But even before that, in 2012, a Chinese hacker group got access to Juniper's source code repositories and essentially updated the backdoor with their own secret key. This gave them potentially full control over critical network equipment and allowed to decrypt VPN traffic for at least three years until it was revealed that, oh no, it's not NSA, but other countries' intelligence is privy to our data. What a shock, indeed. Oh no.
If we go even lower level, here's an interesting one: undocumented instructions added by a Chinese manufacturer to Bluetooth chips used in billions of devices. What's even scarier, in 2016, researchers from the University of Michigan has proved that by means of a microscopic, basically undetectable change on a processor silicon, it is possible to plant a hardware backdoor. A backdoor that can give an attacker full access to an operating system. A backdoor that is exploitable remotely. If you want to know the details, there is an article which you can find in the episode's GitHub link.
So because of all that, I think that we, the worldwide IT industry, are essentially at war. Cyber criminals, private companies, domestic and foreign governments are planting backdoors to spy, control, and steal. The question is, what can we possibly do about it?
Some bloggers are trying to find technical solutions to protect us from attacks like Shy Hulk. This gentleman, for example, suggests to use a tool that acts as a wrapper for npm install. Essentially, it's like an antivirus on Windows, preventing a package download if it contains malware. But the problem with any antivirus is that in most of the cases, it can only detect something it knows about. And if you've ever heard of polymorphic viruses, you know that antiviruses are essentially useless against them. And after all, using tools like this is a reactive measure. You are always at least one step behind the other party.
A better proactive measure was proposed by this well-known streamer. "I keep saying this, don't auto-upgrade patch versions. It's like a massive security vulnerability. This is like the easiest way to be had ever, yet it just keeps happening. Why? Why do you keep doing it? Say no. Lock your versions." Primagen also proposes to get rid of smaller dependencies altogether by generating replacement code with LLMs. Yes, it totally makes sense to replace packages like uneven. An even more radical proposal I saw from the creator of Odin programming language, by the way, is to ditch all package managers altogether and instead to check each dependency manually, copy to your source code and patch by yourself as necessary. Of course, maybe it works with Odin, but I'm personally not sure if it's a viable solution for a language like Python or, yes, server-side JavaScript.
While I think that of course proactive measures are better than reactive, probably the most important thing that really makes a difference is protecting yourself from phishing. "You say, 'Oh, I would never fall for a phishing attempt like this. I'm too smart. I'm big brain developer man.' I don't believe you. Never, never click on links in emails even if you think that you know the sender, or simply spend 5 minutes and reconfigure your mail client to do nothing when you click on links. This is what I did." One more must-have technical thing in my opinion is an application-level firewall like OpenSnitch. I use it for many years on every laptop I own. You will be surprised to see how many things are calling back home on an open-source operating system. And yes, use your MFA, but not regard your email inbox or a mobile phone as such.
Apart from these tips, I don't believe any technical solutions can help much in the backdoors war. If you aren't going to write your own operating system without the network stack, of course, like Terry did, no stable distribution, no tailor-made vulnerability scanner, no dependency locking will save you from the next worm or carefully crafted modification of a critical system package because, as I said, engineers working on the next backdoor are not stupid, and maybe they even have an unlimited budget.
What I think will help is a change of behavior. The first thing we have to do, therefore, is to accept we are at war. And in this regard, I often recall a phrase I've heard on a podcast from an investigator working with high-ranking whistleblowers. This investigator said that the way he lives his daily life is with an assumption that his phone is always tapped. This, if you think about it, is a change in behavior that always keeps you focused. If we accept and always keep in mind that everything is backdoored by default, we are not going to leave any credentials lying in the plain sight. We are not going to let that quick hack, because it's temporary, because it's just a development environment, go through. We have to slow down.
Yes, I know that our industry is in crisis. I have a bunch of friends in the US that struggled to find a job for more than six months, each of them having at least one FAANG company in their resumes. No business seems to plan for longer term. The pressure only grows to deliver quick results because of the competition, because of shareholders, because of AI arms race. And yet, I'm saying that we, the people building things and keeping things running, have to slow down. I know it's tempting to just throw that boring task at an LLM, and sure, there is nothing wrong about it, but just think about it. In the 70s, when tons of things we still use to this day were created by just a handful of smart people. In those times, people wrote code in editors that made you think before you type. Slow down. Think, do you really need this new class, this dependency? When you are slow, you are in charge. You are not going to push your responsibility to that random person on the internet with a GitHub repository because, hey, his or her package looks legit and will save me 15 minutes of my time.
I know many of us are overworked, but if you are tired, please, please get some rest. Research indicates that fatigue affects everyone equally, no matter your age, gender, and so on. Fatigue leads to workplace errors. This was probably an expectation from an attacker who tried to backdoor the Linux kernel in 2003. If a reviewer is tired, this line is more likely to slip through. So again, please get some rest.
And finally, always improve your fundamental knowledge. This will allow you to make better decisions. If you want to improve your understanding of your programming language of choice, I can only recommend CodeCrafters. This is not LeetCode, which maybe stretches your brain but doesn't really help you at your workplace. With CodeCrafters, you work on real projects, building them step by step with just enough guidance. Sign up to CodeCrafters with my referral link to improve your real-world programming mastery and help fund my research for this channel. You can also tip me on my coffee page. By the way, good people, be nice to yourselves and to your fellow open-source maintainers. If you're interested to read more about the topic of this video, click on the link in the description to go to my GitHub with links to extra materials. And yeah, please subscribe. Thank you for watching and see you next time. Love you all. Bye.