Open source groups say more software projects may have been targeted for sabotage

open source groups say more software projects may have been targeted for sabotage

FILE PHOTO: Figurines with computers and smartphones are seen in front of the words “Cyber Security” in this illustration taken, February 19, 2024. REUTERS/Dado Ruvic/Illustration/File Photo

By Raphael Satter

WASHINGTON (Reuters) -The recent attempt by an unknown actor to sabotage a widely used software program may have been one of several attempts to subvert key pieces of digital infrastructure across the internet, two open source groups said in an alert published on Monday.

In a joint statement, the Open Source Security Foundation and the OpenJS Foundation said the attempt to insert a secret backdoor into XZ Utils – a little-known program that is baked into Linux operating systems across the world – “may not be an isolated incident.”

They said at least three different JavaScript projects were targeted by unnamed individuals demanding suspicious updates or asking to be made maintainers of the targeted software.

The JavaScript programming language powers much of the modern web and sees intensive use across the world. Omkhar Arasaratnam, the Open Source Security Foundation’s general manager, said that one of the targeted packages alone saw tens of millions of downloads a week.

He declined to identify the JavaScript projects by name, saying he wanted to protect an ongoing investigation.

Arasaratnam also said that while it wasn’t clear what the suspected malicious actors were hoping to do – “we stopped them before they got that far” – he suspected they hoped to build backdoors into those projects as well.

The OpenJS and Open Source Security Foundations said they had warned the U.S. Cybersecurity & Infrastructure Security Agency about the suspected infiltration. The agency did not immediately return a message seeking comment.

(Reporting by Raphael Satter; Editing by Josie Kao and Leslie Adler)

News Related

OTHER NEWS

Paul Hosford: Helen McEntee's future depends on the streets of Dublin remaining peaceful

Paul Hosford: Helen McEntee’s future depends on the streets of Dublin remaining peaceful The issue of policing in Dublin has been thrown into sharp focus following the horrific stabbing of ... Read more »

Five hospitalised following 'serious' two vehicle road traffic collision

The collision occurred on Monday morning. (stock image) Five people have been hospitalised following a two vehicle road traffic collision on Monday. Gardaí are appealing for witnesses to the collision, ... Read more »

Challenge: Try to find the hidden cat in a very old building

Challenge: Try to find the hidden cat in a very old building (Photo: Reproduction/Reddit) Only people with advanced observation skills can identify the hidden cat in this very old building. ... Read more »

Man arrested following suspected cocaine seizure in Galway worth €56,000

A man has been arrested following a seizure of cocaine with a value of €56,000 in Galway on Sunday evening. Gardaí seized the drugs during a search at a residence ... Read more »

Parkinson's Disease Warning Signs: What To Look Out For

generic doctor image Overview A chronic and progressive movement disorder that initially causes tremor in one hand, stiffness or slowing of movement. Symptoms If you or someone you know is ... Read more »

Man caught with over €1M worth of cocaine in van has jail time doubled in appeal

A man who was caught with over €1 million in cocaine in a “sophisticated” operation where the drugs were hidden in a modified compartment in his van has had his ... Read more »

Fine Gael TD Fergus O'Dowd announces he will stand down after the next General Election

File image of Fine Gael TD Fergus O’Dowd. FINE GAEL TD Fergus O’Dowd has announced that he will stand down at the next General Election. O’Dowd started his political career ... Read more »
Top List in the World