Mon–Fri · 6 AM ET
← All Episodes
EP  • 00:12:24

I found 10k GitHub repositories distributing Trojan malware | Build or Be Replaced

Today: I found 10k GitHub repositories distributing Trojan malware | Zero-Touch OAuth for MCP | Ubiquiti: Enterprise NAS, Built on ZFS Episode date: 2026-06-19.

Download MP3 →

Transcript

JOSH: It's Friday, June 19. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson.
ERIK: Trust is the new attack surface. Code, auth, storage, agents. Same story, different door.
JOSH: Stick around — Erik's got an AI pro tip at the end about using agents without giving them the keys to the building.
[pause]
JOSH: ScanBrief scored 104 items across 54 sources today. First headline: a researcher found 10,000 GitHub repositories distributing Trojan malware. Erik, how bad is that?
ERIK: Bad, but not surprising. Attackers figured out that cloned repos with clean-looking history feel safer than random zip files, so now the supply chain is the payload delivery system.
JOSH: Next up, Zero-Touch OAuth for MCP. That sounds boring until you realize every company is trying to plug agents into internal tools.
ERIK: Exactly. Enterprise-Managed Authorization for MCP means identity lives with the company, not in every little app consent screen. That's the right direction if agents are going to touch real systems.
JOSH: Third headline: Ubiquiti announced an enterprise NAS built on ZFS. Why did that jump out?
ERIK: Because storage vendors love turning basic reliability into a licensing maze. ZFS is boring in the best way. Checksums, snapshots, replication. Give me boring storage every day.
[pause]
JOSH: Let's start with the GitHub malware story. Ten thousand repos is a big number. What's actually happening there?
ERIK: The trick is simple. Clone a real project. Keep the same name. Keep the description. Keep the commit history. Make it look like normal open source. Then change the README so it points people at a zip file with malware in it.
[beat]
ERIK: That's nasty because humans are pattern matchers. We see stars, commits, familiar project names, and our brain says, fine, this is probably okay. The attacker doesn't need to break GitHub. They just need to look enough like GitHub.
JOSH: Wait, really? That's enough?
ERIK: For a lot of people, yes. Especially when they're moving fast. Developer searches for a library, finds a repo, copies the install instructions, runs a command, and now the machine is part of the story.
JOSH: So the weak point isn't GitHub itself. It's the habit.
ERIK: Right. The weak point is trust by vibes. That's not a security model. That's a coin flip with syntax highlighting.
[beat]
JOSH: How do you defend against that without making developers hate their lives?
ERIK: You put checks in the path where work already happens. Don't ask everyone to become a malware researcher before lunch. Use dependency pinning. Verify package origins. Block random archive downloads in build steps. Require signed releases where you can. Scan READMEs for external binary links if your org pulls from GitHub at volume.
JOSH: Scan the README?
ERIK: Absolutely. The README is part of the attack path now. If a repo says, hey download this release zip from a weird domain, that's not documentation. That's a flare.
JOSH: How would you wire that into your setup?
ERIK: PrimeBus already treats events like first-class citizens. Today it processed 793 automation events across 12 projects. That means I don't need every tool to know about every other tool. A repo scanner can emit an event that says, suspicious external archive link found. Gandalf can review it. A policy agent can block the build. A human only gets pulled in when the system can't make a clean call.
[beat]
ERIK: That's the pattern. Events first. Agents subscribe. Guardrails decide. Humans handle the weird stuff.
JOSH: That sounds very enterprise. But your lab is not a giant company.
ERIK: That's the point. You don't need a giant company to need real controls. I have 121 services running on the production server right now. If I let every service pull random code from random places, I'm not building automation. I'm building a haunted vending machine.
JOSH: That's the dry version of a breach report.
ERIK: Pretty much.
[beat]
JOSH: Where does AI make this worse?
ERIK: Code agents will happily follow instructions from poisoned repos if you let them. If an agent reads a README that says run install.sh, and your prompt says follow the repo instructions, congrats. You gave malware a product manager.
JOSH: That's grim.
ERIK: It's accurate. Agentic coding changes the blast radius. A junior dev might hesitate before running a weird script. An agent won't hesitate unless you gave it policy, sandboxing, and a reason to stop.
JOSH: So what's the rule?
ERIK: Agents can read almost anything. They should execute almost nothing by default. Especially shell scripts, install scripts, package postinstall hooks, Dockerfiles from unknown repos, and anything that reaches outside the repo during build.
[pause]
JOSH: That leads right into the MCP OAuth story. For people who aren't buried in agent tooling, what's MCP in plain English?
ERIK: MCP is a way for AI tools to connect to other tools. Files, databases, Slack, GitHub, cloud APIs, internal systems. It gives the model hands.
JOSH: And OAuth is the permission part.
ERIK: Yep. OAuth is how the app gets permission to do things on your behalf. The problem is, when every MCP server asks every user for consent, you get a pile of prompts, tokens, scopes, and weird little trust decisions that no normal person wants to make.
JOSH: So Zero-Touch OAuth removes that?
ERIK: It moves the decision where it belongs. Enterprise-Managed Authorization means the organization controls access through the identity provider. The user doesn't approve every little connection. The company says this group can use this MCP server with these scopes under these conditions.
[beat]
JOSH: That sounds like what IT has wanted all along.
ERIK: It is. And it's necessary. If agents are going to touch ticketing systems, routers, Kubernetes clusters, CRM records, invoices, or production databases, consent prompts are not governance. They're theater.
JOSH: What's the danger if companies skip this?
ERIK: Tool sprawl. Token sprawl. Unknown agents with unknown access. Someone connects a desktop AI client to a sensitive MCP server, grants broad permissions, leaves the company, and nobody knows which token is still alive.
JOSH: That's the nightmare version.
ERIK: That's the normal version if nobody designs the system. I've seen this movie with API keys, SSH keys, service accounts, Jenkins credentials, Terraform state, NSO credentials. Different decade, same mess.
[beat]
JOSH: How would you build it?
ERIK: Start with identity. Groups, roles, scopes. Then split tools by risk. Low-risk tools can read docs or search tickets. Medium-risk tools can open pull requests or draft changes. High-risk tools can touch prod only through a controlled workflow.
JOSH: Not direct access.
ERIK: Never raw direct access for serious systems. If an agent wants to change a router config, it should propose the change, run validation, compare intent, check blast radius, and then hand it to a controlled pipeline. Cisco NSO does that style of thing well because intent and service models matter. Terraform does it with plans. Kubernetes does it with admission control. Same philosophy.
JOSH: Where does PrimeBus fit into that?
ERIK: PrimeBus is the control plane for my agents. Eleven agents in the Bobaverse fleet emit and consume telemetry. Neo, Homer, Bill, Echo, Gandalf, Claude plus GPT. That sounds cute until you realize the important part is the bus, not the names.
[beat]
ERIK: Every action becomes an event. Every event can be reviewed. One code change was automatically reviewed by Gandalf and merged to production overnight. That only works because the pipeline has gates.
JOSH: And the live stats say 697 merged, 368 blocked by Gandalf, 0 escalated to you since June 5.
ERIK: That's the story. The blocked count matters. People hear blocked and think failure. No. Blocked means the guardrail worked. Zero escalated to me means the system either had enough confidence to merge or enough sense to stop.
JOSH: That's a very different way to measure automation.
ERIK: Most people measure how much the robot did. I care how much damage the robot didn't do.
[pause]
JOSH: Let's hit the Ubiquiti NAS story. ZFS in an enterprise NAS from Ubiquiti. Why does that matter to builders?
ERIK: Storage is where good intentions go to die. You can rebuild an app. You can redeploy a service. Lose the data and suddenly everyone finds religion.
JOSH: That's the quote.
ERIK: ZFS matters because it assumes disks lie. It checksums data. It can detect corruption. It can snapshot. It can replicate. It gives you primitives that make sense when you care about uptime and recovery.
JOSH: And Ubiquiti is making that more accessible?
ERIK: That's the interesting part. Enterprise storage has been wrapped in proprietary hardware, support contracts, and license tiers forever. Ubiquiti coming in with a ZFS-based NAS says the boring reliable stuff should be easier to buy and manage.
[beat]
JOSH: Does that replace the big storage vendors?
ERIK: Not everywhere. If you're a bank with petabytes and compliance teams, you're not ripping everything out because a new box looks cool. But for labs, small businesses, agencies, edge sites, schools, and teams that need sane storage without selling a kidney, this is useful.
JOSH: How do you think about storage in your own systems?
ERIK: Backups first. Then snapshots. Then replication. Then restore testing. People love to talk about backup products. I care about the restore. If you haven't restored it, you don't have a backup. You have a bedtime story.
JOSH: That's painfully true.
ERIK: My PAS website-pipeline is a good example. It can build and maintain sites autonomously, but the boring part matters more than the flashy part. Source control. Artifact storage. Rollback. DNS records. Logs. If the agent makes a bad change, I need to roll back fast and know exactly what happened.
[beat]
JOSH: So this connects back to agents again.
ERIK: Everything connects back to agents now. An agent can generate content. It can change configs. It can build a site. BookForge can push edits through a multi-book backend. That's powerful. But if storage, identity, and audit trails are weak, the agent becomes the fastest way to make a mess.
JOSH: Is that why you keep saying infrastructure is the product?
ERIK: Yes. The UI is what people see. The infrastructure is what decides whether you sleep. Real builders care about queues, logs, state, rollback, and permissions. That's where the money is.
JOSH: Where does ScanBrief fit in?
ERIK: ScanBrief is the radar. It scored 104 items across 54 sources today, but the point isn't the count. The point is signal. It shows me what changed. Then I decide what belongs in the stack, what belongs in the trash, and what belongs in tomorrow's automation.
[beat]
JOSH: So today's pattern is trust, but across three layers.
ERIK: Exactly. GitHub malware is trust in code. MCP OAuth is trust in tools. ZFS NAS is trust in data. Same question every time: what do you trust, why do you trust it, and what happens when it lies?
JOSH: That's a clean way to frame it.
ERIK: Builders need to stop treating trust like a feeling. Trust is something you instrument. Logs. Checks. Policies. Reviews. Rollbacks. If you can't observe it, you don't trust it. You hope it behaves.
[pause]
ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com
[pause]
JOSH: Alright, what's the AI pro tip today?
ERIK: Give your coding agent a deny list before you give it a task. Not after. Put it in the system prompt or repo instructions.
[beat]
ERIK: Say this clearly: do not run remote install scripts, do not curl pipe to shell, do not modify production secrets, do not change CI permissions, do not add broad OAuth scopes, and do not execute files downloaded from unknown repos.
JOSH: That's pretty specific.
ERIK: Specific is the point. Vague safety prompts are decoration. Give the agent concrete forbidden actions, then make it explain when it needs an exception. If it needs to run something risky, it should stop and ask. Same as a junior engineer with root access.
[beat]
ERIK: Bonus move: log every blocked action. Those logs become your policy backlog. If agents keep trying the same risky move, fix the workflow, don't just yell at the model. That's your tip. Use it.
[pause]
JOSH: Binge all five episodes this weekend plus our YouTube shorts — links at buildorbereplaced.dev.
[pause]
JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev.
ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff.
[pause]
ERIK: Build or be replaced.
JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.