More threats against open source software could be coming soon, experts warn

JavaScript code on a computer screen
(Image credit: Shutterstock / BEST-BACKGROUNDS)

The recent attack on the XZ Utils supply chain was not an isolated incident, but rather part of a larger social engineering campaign that sought to compromise numerous JavaScript projects, experts have warned.

In a joint blog post, the OpenSource Security Foundation (OSSF) and OpenJS Foundation said that the OpenJS Foundation Cross Project Council received “a suspicious series of emails” all similar to one another, and mentioning similar GitHub-associated emails. 

In the message, the senders urged OpenJS to update one of its popular JavaScript projects to “address any critical vulnerabilities”. Furthermore, they asked to be made new maintainers of the projects - something that was apparently done in the XZ Utils supply chain attack.

False sense of urgency

The attacks were, fortunately, not successful, the blog adds, as none of these individuals were given any privileged access.

Still, maintainers should be wary of “friendly yet aggressive and persistent” people demanding maintainer status for different projects - especially people who are relatively unknown members of the community. Even people endorsing such individuals shouldn’t be fully trusted, as they are most likely “sock puppets” - people with fake identities all working towards the same goal. 

Finally, the attackers will try to establish a false sense of urgency, all so that the maintainers drop their guard and grant them privileged access.

“These social engineering attacks are exploiting the sense of duty that maintainers have with their project and community in order to manipulate them,” the researchers warn. “Pay attention to how interactions make you feel. Interactions that create self-doubt, feelings of inadequacy, of not doing enough for the project, etc. might be part of a social engineering attack.”

XZ-utils, a set of data compression tools and libraries used by major Linux distros, was found vulnerable to CVE-2024-3094. The flaw was introduced to XZ version 5.6.0 by a pseudonymous attacker, and persisted throughout 5.6.1 as well. The discovery of the vulnerability pushed the release of Ubuntu 24.04 beta for a week.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Huge cybercrime attack sees 390,000 WordPress websites hit, details stolen
A white padlock on a dark digital background.
Developers targeted by malicious Microsoft VSCode extensions
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
Cyber-security
Top file-sharing tools are being hit by security attacks once again
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
The Python banner logo on a computer screen running a code editor.
More malicious Python packages are on the loose, experts warn
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection