Alert for Social Engineering Takeovers of Open Source Projects

[email protected] (Nelson Ferraz) Mon, 6 May 2024 14:41:05 +0200
Newsgroups perl.module-authors
Message-ID <CAG+zsv2j8B6Pd6QFbiRiM6PBL1SkRJGYyhmZ4PmpnsM_jinVXQ@mail.gmail.com>
--000000000000afa01a0617c86295
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

The recent attempted XZ Utils backdoor (CVE-2024-3094) may not be an
isolated incident as evidenced by a similar credible takeover attempt
intercepted by the OpenJS Foundation, home to JavaScript projects used by
billions of websites worldwide. The Open Source Security (OpenSSF) and
OpenJS Foundations are calling all open source maintainers to be alert for
social engineering takeover attempts, to recognize the early threat
patterns emerging, and to take steps to protect their open source projects.
(...)

Suspicious patterns in social engineering takeovers:

* Friendly yet aggressive and persistent pursuit of maintainer or their
hosted entity (foundation or company) by relatively unknown members of the
community.
* Request to be elevated to maintainer status by new or unknown persons.
* Endorsement coming from other unknown members of the community who may
also be using false identities, also known as =E2=80=9Csock puppets.=E2=80=
=9D
* PRs containing blobs as artifacts.
   * For example, the XZ backdoor was a cleverly crafted file as part of
the test suite that wasn=E2=80=99t human readable, as opposed to source cod=
e.
* Intentionally obfuscated or difficult to understand source code.
* Gradually escalating security issues.
   * For example, the XZ issue started off with a relatively innocuous
replacement of safe_fprintf() with fprintf() to see who would notice.
* Deviation from typical project compile, build, and deployment practices
that could allow the insertion of external malicious payloads into blobs,
zips, or other binary artifacts.
* A false sense of urgency, especially if the implied urgency forces a
maintainer to reduce the thoroughness of a review or bypass a control.

These social engineering attacks are exploiting the sense of duty that
maintainers have with their project and community in order to manipulate
them. Pay attention to how interactions make you feel. Interactions that
create self-doubt, feelings of inadequacy, of not doing enough for the
project, etc. might be part of a social engineering attack.

https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs=
-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-pr=
ojects/

--=20
Nelson Ferraz

--000000000000afa01a0617c86295
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>The recent attempted XZ Utils backdoor (CVE-2024-3094=
) may not be an isolated incident as evidenced by a similar credible takeov=
er attempt intercepted by the OpenJS Foundation, home to JavaScript project=
s used by billions of websites worldwide. The Open Source Security (OpenSSF=
) and OpenJS Foundations are calling all open source maintainers to be aler=
t for social engineering takeover attempts, to recognize the early threat p=
atterns emerging, and to take steps to protect their open source projects. =
(...)</div><div><br></div><div><font size=3D"4">Suspicious patterns in soci=
al engineering takeovers:</font></div><div><br>* Friendly yet aggressive an=
d persistent pursuit of maintainer or their hosted entity (foundation or co=
mpany) by relatively unknown members of the community.<br>* Request to be e=
levated to maintainer status by new or unknown persons.<br>* Endorsement co=
ming from other unknown members of the community who may also be using fals=
e identities, also known as =E2=80=9Csock puppets.=E2=80=9D<br>* PRs contai=
ning blobs as artifacts.<br>=C2=A0 =C2=A0* For example, the XZ backdoor was=
 a cleverly crafted file as part of the test suite that wasn=E2=80=99t huma=
n readable, as opposed to source code.<br>* Intentionally obfuscated or dif=
ficult to understand source code.<br>* Gradually escalating security issues=
.<br>=C2=A0 =C2=A0* For example, the XZ issue started off with a relatively=
 innocuous replacement of safe_fprintf() with fprintf() to see who would no=
tice.<br>* Deviation from typical project compile, build, and deployment pr=
actices that could allow the insertion of external malicious payloads into =
blobs, zips, or other binary artifacts.<br>* A false sense of urgency, espe=
cially if the implied urgency forces a maintainer to reduce the thoroughnes=
s of a review or bypass a control.<br><br></div><div>These social engineeri=
ng attacks are exploiting the sense of duty that maintainers have with thei=
r project and community in order to manipulate them. Pay attention to how i=
nteractions make you feel. Interactions that create self-doubt, feelings of=
 inadequacy, of not doing enough for the project, etc. might be part of a s=
ocial engineering attack.<br><br><a href=3D"https://openssf.org/blog/2024/0=
4/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-so=
cial-engineering-takeovers-of-open-source-projects/">https://openssf.org/bl=
og/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-ale=
rt-for-social-engineering-takeovers-of-open-source-projects/</a><br></div><=
div><div><br></div><span class=3D"gmail_signature_prefix">-- </span><br><di=
v dir=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_signature">=
Nelson Ferraz</div></div></div>

--000000000000afa01a0617c86295--