Categories: CyberCrimeSecurity

Open Source Groups Warn Of Ongoing Attacks

Two open source groups have warned of ongoing takeover attempts by malicious actors similar to one that affected a widely used component earlier this month.

Researchers at the OpenJS Foundation, which backs JavaScript-based projects, and the Open Source Security Foundation (OpenSSF) said they had blocked a “credible” hacking attempt affecting a popular JavaScript project and warned that other attacks may follow.

The researchers said a developer “wanted OpenJS to designate them as a new maintainer of the project despite having little prior involvement”, said OpenJS Foundation executive director Robin Bender Ginn and OpenSSF general manager Omkhar Arasaratnam in a joint statement.

The moves recalled a recent infiltration effort by a threat actor going by the name “Jia Tan” that targeted XZ Utils, a compression tool widely used in Linux systems, Ginn and Arasaratnam said.

Open source attacks

The attack on XZ Utils was developed over several years until it was finally uncovered earlier this month.

The researchers said OpenJS did not grant privileged access to the project that was targeted, adding that two other popular JavaScript projects that OpenJS does not host had also seen suspicious patterns.

OpenJS has reported the incident to the Cybersecurity and Infrastructure Security Agency (CISA) and the US Department of Homeland Security.

The researchers warned open source developers to remain alert for further attempts to compromise open source projects via social engineering methods.

Vulnerable ecosystem

Chris Hughes, chief security advisor at open source security company Endor Labs and a Cyber Innovation Fellow at CISA, said about one-quarter of all open source security projects have only one maintainer, with 94 percent having fewer than 10.

He said the open source ecosystem is highly opaque, with projects critical to digital infrastructure being maintained by individuals scattered around the world and often using unknown aliases.

“Many OSS projects are maintained by a single individual or small group of individuals – often in their spare time as a hobby or passion project and typically without any sort of compensation,” he said.

“This makes the entire ecosystem vulnerable to malicious actors preying on these realities and taking advantage of overwhelmed maintainers with a community making demands of them with no actual compensation in exchange for their hard work and commitment to maintaining code the world depends on.”

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Google Digital Ad Network Ruled Illegal Monopoly By Judge

More bad news for Google. Second time in less than a year that some part…

15 hours ago

US State Dept Closes Office Flagging Russia, China Disinformation

Federal office that tackled misinformation and disinformation from hostile nations is closed down, after criticism…

17 hours ago

Nvidia CEO Jensen Huang Makes Surprise Visit To China

After Nvidia admits it will take $5.5 billion charge as Trump export limits of slower…

17 hours ago

Former CISA Chief Chris Krebs Targetted By Trump Executive Order

Trump continues to target his former CISA head, signing a new executive order targetting Chris…

18 hours ago

Temu, Shein To Increase US Prices After Trump’s Tariffs

Two Chinese retailers warn customers in America that prices will increase next week, as Trump's…

22 hours ago

Tesla Whistleblower Wins Legal Ruling Against Elon Musk

Engineer Cristina Balan wins latest round in her long-running defamation claim against Elon Musk's EV…

23 hours ago