More threats against open source software could soon arrive, experts warn

The recent attack on XZ Utils' supply chain was not an isolated incident, but part of a broader social engineering campaign that sought to compromise numerous JavaScript projects, experts warned.

In a joint blog post, OpenSource Security Foundation (OSSF) and OpenJS Foundation said that the OpenJS Foundation Cross Project Council received “a suspicious series of emails,” all similar to each other, and mentioning similar emails associated with GitHub.

scroll to top