logo

OpenSSF Flags Malware Campaign on Slack Posing as Linux Foundation Figures

ID: 3c9fc367-880f-5812-8dc6-ed8580fa1924

STIX ID: report--3c9fc367-880f-5812-8dc6-ed8580fa1924

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**OpenSSF warns of a targeted Slack phishing campaign** that impersonates community leaders to lure developers to a fake Google Workspace flow; victims are asked to provide credentials and install a malicious root certificate that enables encrypted-traffic interception, and macOS users may be served a 'gapi' payload capable of full system takeover. The campaign targeted the TODO Group Slack workspace, used a now-deleted Sites link and fake identifiers, and resembles prior developer-targeting operations reportedly linked to North Korean state-sponsored actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.