all InfoSec news
Other Attempts to Take Over Open Source Projects
Schneier on Security www.schneier.com
After the XZ Utils discovery, people have been examining other open-source projects. Surprising no one, the incident is not unique:
The OpenJS Foundation Cross Project Council received a suspicious series of emails with similar messages, bearing different names and overlapping GitHub-associated emails. These emails implored OpenJS to take action to update one of its popular JavaScript projects to “address any critical vulnerabilities,” yet cited no specifics. The email author(s) wanted OpenJS to designate them as a new maintainer of the …
action backdoors council discovery emails foundation github incident messages names openjs openjs foundation open source people project projects series social engineering update xz utils