logo

Open sourcerers say suspected xz-style attacks continue to target maintainers

ID: 6053808f-29c2-5fb3-9eee-153a0b139416

STIX ID: report--6053808f-29c2-5fb3-9eee-153a0b139416

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-04-16

Date Updated: 2026-04-26

Author: Connor Jones

...
...

OpenJS Foundation and OpenSSF warn of a wave of social-engineering attempts aimed at elevating malicious actors to maintainer status in open-source projects, citing similarity to the recent attempted backdoor in the xz/liblzma library. The report describes suspicious GitHub-associated emails and sockpuppet endorsements, examples of obfuscated or unusual code changes, and deviations from normal build and release processes; it urges maintainers to be vigilant and recommends increased funding and support for security measures across the open-source ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.