After Xz Utils, More Open-source Software Under Attack

13 Days(s) Ago    👁 52
after xz utils more opensource software under attack

The recent attempt by an unknown actor to sabotage a widely used software program may have been one of several attempts to subvert key pieces of digital infrastructure across the internet, two open-source groups said in an alert published on Monday.

In a joint statement, the Open Source Security Foundation and the OpenJS Foundation said the attempt to insert a secret backdoor into XZ Utils , a little-known program that is baked into Linux operating systems across the world, may not be an isolated incident.

They said at least three different JavaScript projects were targeted by unnamed individuals demanding suspicious updates or asking to be made maintainers of the targeted software.

The JavaScript programming language powers much of the modern web. Omkhar Arasaratnam, the Open Source Security Foundations GM, said that one of the targeted packages alone saw tens of millions of downloads a week.

' READ: Linux on the desktop is gaining ground

The OpenJS and Open Source Security Foundations said they had warned the US Cybersecurity Infrastructure Security Agency about the suspected infiltration. The agency did not immediately return a message seeking comment. Raphael Satter, (c) 2024 Reuters