logo

Putin on the code: DoD reportedly relies on utility written by Russia-based Yandex dev

ID: 9b2ef22e-f70e-555d-8c3e-e42c532a80d5

STIX ID: report--9b2ef22e-f70e-555d-8c3e-e42c532a80d5

Feed Name: The Register (Security)

Date Published: 2025-08-27

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

A report highlights supply chain risk concerns about the Node.js package fast-glob, which is widely used (including in DoD projects) and maintained by a single developer identified as a Yandex employee in Russia. While no CVEs, compromises, or threat actor ties are reported and the maintainer denies any malicious activity, the potential for exploitation due to deep system access is noted; recommended mitigations include adding maintainers and improving oversight or replacing the package.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.