logo

Linux Foundation Leader Impersonated in Slack Attack on Open Source Developers

ID: b6f83abe-b253-5d43-b7cd-92b1e5717d15

STIX ID: report--b6f83abe-b253-5d43-b7cd-92b1e5717d15

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A targeted social-engineering campaign is actively infiltrating Slack communities for open-source developers, impersonating known maintainers to phish credentials and convince victims to install a malicious root certificate (or, on macOS, run a downloaded binary named "gapi"), enabling TLS interception and potential full system compromise; OpenSSF advises stricter identity verification, avoiding unsolicited certificates/binaries, disconnecting and rotating credentials if compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.