The Open Source Security Foundation and the OpenJS Foundation issued an alert warning that attackers are using social engineering to seize control of open-source projects by targeting maintainers and trusted contributors. The warning highlighted account takeovers, fraudulent outreach, and other tactics that can give adversaries the ability to publish malicious updates through legitimate projects, creating downstream risk for organizations that depend on widely used packages and developer tooling.
OpenSSF later published guidance for maintainers on hardening CI/CD pipelines after the tj-actions and reviewdog supply-chain incidents, emphasizing stronger identity verification, tighter repository and workflow permissions, protection for release processes, and closer monitoring of automation used to build and distribute software. Together, the alerts describe a growing pattern in which attackers compromise trust in the open-source ecosystem and then abuse build and release infrastructure to propagate malicious code to users at scale.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
OpenSSF published guidance for maintainers on securing CI/CD pipelines in response to the tj-actions and reviewdog supply-chain attacks. The post reflects public acknowledgment of those incidents and recommended defensive measures.
OpenSSF and the OpenJS Foundation issued an alert about social-engineering attacks leading to takeovers of open-source projects. The alert marked a public warning to maintainers about this threat pattern.
Dragos published a report titled "ELECTRUM KAMASITE 10 Year Retrospective" covering activity targeting Poland's electric sector. The reference indicates the campaign and its historical analysis were publicly documented by this date.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
openssf.org
Open sourceopenssf.org
Open sourcehub.dragos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.