iTnews Asia
  • Home
  • News
  • Security

Open Source groups warn of increased software sabotage risk

Open Source groups warn of increased software sabotage risk

At least three different JavaScript projects were targeted.

By Raphael Satter on Apr 16, 2024 11:40AM

The recent attempt by an unknown actor to sabotage a widely used software program may have been one of several attempts to subvert key pieces of digital infrastructure across the internet, two open source groups said in an alert published on Monday.

In a joint statement, the Open Source Security Foundation and the OpenJS Foundation said the attempt to insert a secret backdoor into XZ Utils - a little-known program that is baked into Linux operating systems across the world - "may not be an isolated incident."

They said at least three different JavaScript projects were targeted by unnamed individuals demanding suspicious updates or asking to be made maintainers of the targeted software.

The JavaScript programming language powers much of the modern web and sees intensive use across the world. Omkhar Arasaratnam, the Open Source Security Foundation's general manager, said that one of the targeted packages alone saw tens of millions of downloads a week.

He declined to identify the JavaScript projects by name, saying he wanted to protect an ongoing investigation.

Arasaratnam also said that while it wasn't clear what the suspected malicious actors were hoping to do - "we stopped them before they got that far" - he suspected they hoped to build backdoors into those projects as well.

The OpenJS and Open Source Security Foundations said they had warned the US Cybersecurity & Infrastructure Security Agency about the suspected infiltration. The agency did not immediately return a message seeking comment.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright Reuters
© 2019 Thomson Reuters. Click for Restrictions.
Tags:
open source security

Related Articles

  • Your organisation’s physical security can be a gateway for cybercriminals
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Your organisation’s physical security can be a gateway for cybercriminals

Your organisation’s physical security can be a gateway for cybercriminals

The best way to outsmart your threat actors is to think like one

The best way to outsmart your threat actors is to think like one

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.