After XZ Utils, More Open-Source Maintainers Under Attack

Open link in next tab

After XZ Utils, More Open-Source Maintainers Under Attack

https://www.bankinfosecurity.com/after-xz-utils-more-open-source-maintainers-under-attack-a-24870

Major open-source software projects are warning that more pieces of code than XZ Utils may have been backdoored by attackers, based on ongoing supply-chain attack

After XZ Utils, More Open-Source Maintainers Under Attack

cross-posted from: https://infosec.pub/post/11143989

Fresh Social Engineering Attacks Resemble Tactics Used Against XZ Utils MaintainerMajor open-source software projects are warning that more pieces of code than XZ Utils may have been backdoored by attackers, based on ongoing supply-chain attack attempts that have targeted "popular JavaScript projects," apparently seeking to trick them into sharing code maintainer rights.