logo

Social engineering attacks on open source developers are escalating

ID: 399370a0-3345-56e1-9d2f-2478d34f8c47

STIX ID: report--399370a0-3345-56e1-9d2f-2478d34f8c47

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-04-08

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

### Executive summary Open-source maintainers (particularly Node.js/npm) have been targeted by an active social-engineering campaign that impersonates recruiters, podcast hosts, and platform representatives to trick developers into installing a RAT or fake certificates via cloned Slack/Teams and phishing pages; attackers have used access to inject malware into widely downloaded npm packages and to harvest credentials and potentially gain full system control. The OpenSSF advisory highlights ongoing impersonation of community leaders, credential-phishing pages that request verification codes and installation of fake root certificates (and macOS binaries), and recommends out-of-band verification, rotating credentials, and reporting incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.