Seriously Risky Business Newsletter
April 18, 2024
Corporate Freeloading Makes Open Source Vulnerable
Presented by
Policy & Intelligence
The foundations for open source software security (OpenSSF) and for the promotion of JavaScript (OpenJS) have jointly warned the takeover of the XZ Utils project (a likely state-backed multi-year effort to subvert an open source project by gaining the trust of the package's maintainer) was probably not an isolated incident.
The foundations said that several 'credible takeover attempts' had been unsuccessfully launched against JavaScript-related projects.
Their post provides a list of "suspicious patterns" of behaviour that could indicate an attempted social engineering attack. The list isn't wrong, but to some degree it misses the point.