Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Social engineering attacks on open source developers are escalating
    Cybersecurity

    Social engineering attacks on open source developers are escalating

    adminBy adminApril 8, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Social engineering attacks on open source developers are escalating
    Share
    Facebook Twitter LinkedIn Pinterest Email

    North Korean hackers spent weeks socially engineering an Axios maintainer through a fake Slack workspace, a cloned company identity, and a fabricated Microsoft Teams call that tricked him into installing a RAT posings as a software update. They used the access they gained to inject malware into npm packages downloaded 100+ million times a week.

    Now, a fresh Open Source Security Foundation (OpenSSF) advisory warns unknown attackers are using a similar approach to target other open source developers.

    The Axios attack was not isolated

    In the wake of the high-profile Axios compromise, Socket researchers learned that the same attack campaign targeted many other open source maintainers – particularly those managing Node.js and npm – as well as several Socket engineers.

    The attackers reach out via LinkedIn or Slack, posing as company owners/representatives, job recruiters, or podcast hosts, and tried to lure developers into downloading malware masquerading as a videoconferencing software update / fix.

    “The attackers used a spoofed Streamyard platform to trick Pelle Wessman, a maintainer of Mocha, into downloading a virus. Another expert, Matteo Collina, nearly fell for a Slack message on 2 April, while others like Scott Motte (creator of dotenv) and John-David Dalton (creator of Lodash) were also targeted,” Socket’s Deeba Ahmed shared.

    “They even went after Socket CEO Feross Aboukhadijeh, the creator of WebTorrent and buffer, who noted that this type of targeting is becoming the ‘new normal.’”

    Now someone is impersonating a Linux Foundation leader

    Christopher Robinson, OpenSSF’s Chief Technology Officer and Chief Security Architect, warns that attackers are currently also impersonating a well-known Linux Foundation community leader and attempting to lure the victim into following a malicious link.

    “The community has received reports of an active social engineering campaign targeting open source developers via Slack (including ToDoGroup and related communities),” he shared through the OpenSSF Siren List.

    The link provided by the attackers (https://sites.google.com/view/workspace-business/join) mimics a legitimate Google Workspace flow, but takes developers to a phishing page where they are asked to enter their login credentials and verification code, then install a fake root “Google certificate”.

    Developers using a Mac also apparently got an additional malicious binary dropped and executed via a script.

    “Installing the certificate enables interception of encrypted traffic and credential theft. Executing the binary may result in full system compromise,” Robinson noted.

    Don’t trust. Verify.

    As open source codebases have become harder to compromise directly, the attack surface has moved and the target, increasingly, is the person who ships the code.

    “Attackers are targeting developer workflows and trust relationships,” Robinson pointed out, and advised devs to verify the identities of those who reach out to them.

    “Do not trust messages based solely on name or profile, and confirm unusual requests through a separate, known communication channel. Be cautious of unsolicited outreach, even from familiar names,” he added.

    Developers should verify whether the login pages they are directed to are legitimate, avoid running software or scripts received via Slack or unknown websites, and be extra careful when faced with messages warning about expired certificates or urgent updates.

    Those who’ve fallen for the trick should consider their system, their credentials, and their active sessions and tokens compromised, and proceed to clean the former and rotate/revoke the latter.

    “Report the incident to your security team or organization,” Robinson also advised, and asked those who have observed similar activity or have additional indicators to share to report them to their security team and share them via appropriate community channels.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    attacks Developers engineering escalating open Social Source
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleLoop Marketing vs. traditional marketing: What’s the difference?
    Next Article How to Get Your Part of the $135 Million Android Settlement
    admin
    • Website

    Related Posts

    April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More

    April 16, 2026

    Windows is getting stronger RDP file protections to fight phishing attacks

    April 16, 2026

    Medium-severity flaw in Microsoft SharePoint exploited

    April 16, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    NYT Strands hints and answers for Thursday, April 16 (game #774)

    April 16, 2026

    The Modern SEO Center Of Excellence: Governance, Not Guidelines

    April 16, 2026

    Raspberry Pi OS is getting a new security measure, and people are already annoyed

    April 16, 2026

    April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More

    April 16, 2026
    Categories
    • Blogging (63)
    • Cybersecurity (1,338)
    • Privacy & Online Earning (168)
    • SEO & Digital Marketing (821)
    • Tech Tools & Mobile / Apps (1,602)
    • WiFi / Internet & Networking (225)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    NYT Strands hints and answers for Thursday, April 16 (game #774)

    April 16, 2026

    The Modern SEO Center Of Excellence: Governance, Not Guidelines

    April 16, 2026

    Raspberry Pi OS is getting a new security measure, and people are already annoyed

    April 16, 2026
    Most Popular
    • NYT Strands hints and answers for Thursday, April 16 (game #774)
    • The Modern SEO Center Of Excellence: Governance, Not Guidelines
    • Raspberry Pi OS is getting a new security measure, and people are already annoyed
    • April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
    • YouTube Premium is now 50% off for certain Google One subscribers
    • Windows is getting stronger RDP file protections to fight phishing attacks
    • Google adds campaign-level filtering to bulk ad review appeals
    • MKBHD pulls back the curtain on LG’s cancelled rollable
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.