Alert for Social Engineering Takeovers of Open Source Projects
[email protected] (Nelson Ferraz) Mon, 6 May 2024 14:41:05 +0200
| Newsgroups | perl.module-authors |
|---|---|
| Message-ID | <CAG+zsv2j8B6Pd6QFbiRiM6PBL1SkRJGYyhmZ4PmpnsM_jinVXQ@mail.gmail.com> |
--000000000000afa01a0617c86295 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable The recent attempted XZ Utils backdoor (CVE-2024-3094) may not be an isolated incident as evidenced by a similar credible takeover attempt intercepted by the OpenJS Foundation, home to JavaScript projects used by billions of websites worldwide. The Open Source Security (OpenSSF) and OpenJS Foundations are calling all open source maintainers to be alert for social engineering takeover attempts, to recognize the early threat patterns emerging, and to take steps to protect their open source projects. (...) Suspicious patterns in social engineering takeovers: * Friendly yet aggressive and persistent pursuit of maintainer or their hosted entity (foundation or company) by relatively unknown members of the community. * Request to be elevated to maintainer status by new or unknown persons. * Endorsement coming from other unknown members of the community who may also be using false identities, also known as =E2=80=9Csock puppets.=E2=80= =9D * PRs containing blobs as artifacts. * For example, the XZ backdoor was a cleverly crafted file as part of the test suite that wasn=E2=80=99t human readable, as opposed to source cod= e. * Intentionally obfuscated or difficult to understand source code. * Gradually escalating security issues. * For example, the XZ issue started off with a relatively innocuous replacement of safe_fprintf() with fprintf() to see who would notice. * Deviation from typical project compile, build, and deployment practices that could allow the insertion of external malicious payloads into blobs, zips, or other binary artifacts. * A false sense of urgency, especially if the implied urgency forces a maintainer to reduce the thoroughness of a review or bypass a control. These social engineering attacks are exploiting the sense of duty that maintainers have with their project and community in order to manipulate them. Pay attention to how interactions make you feel. Interactions that create self-doubt, feelings of inadequacy, of not doing enough for the project, etc. might be part of a social engineering attack. https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs= -foundations-issue-alert-for-social-engineering-takeovers-of-open-source-pr= ojects/ --=20 Nelson Ferraz --000000000000afa01a0617c86295 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>The recent attempted XZ Utils backdoor (CVE-2024-3094= ) may not be an isolated incident as evidenced by a similar credible takeov= er attempt intercepted by the OpenJS Foundation, home to JavaScript project= s used by billions of websites worldwide. The Open Source Security (OpenSSF= ) and OpenJS Foundations are calling all open source maintainers to be aler= t for social engineering takeover attempts, to recognize the early threat p= atterns emerging, and to take steps to protect their open source projects. = (...)</div><div><br></div><div><font size=3D"4">Suspicious patterns in soci= al engineering takeovers:</font></div><div><br>* Friendly yet aggressive an= d persistent pursuit of maintainer or their hosted entity (foundation or co= mpany) by relatively unknown members of the community.<br>* Request to be e= levated to maintainer status by new or unknown persons.<br>* Endorsement co= ming from other unknown members of the community who may also be using fals= e identities, also known as =E2=80=9Csock puppets.=E2=80=9D<br>* PRs contai= ning blobs as artifacts.<br>=C2=A0 =C2=A0* For example, the XZ backdoor was= a cleverly crafted file as part of the test suite that wasn=E2=80=99t huma= n readable, as opposed to source code.<br>* Intentionally obfuscated or dif= ficult to understand source code.<br>* Gradually escalating security issues= .<br>=C2=A0 =C2=A0* For example, the XZ issue started off with a relatively= innocuous replacement of safe_fprintf() with fprintf() to see who would no= tice.<br>* Deviation from typical project compile, build, and deployment pr= actices that could allow the insertion of external malicious payloads into = blobs, zips, or other binary artifacts.<br>* A false sense of urgency, espe= cially if the implied urgency forces a maintainer to reduce the thoroughnes= s of a review or bypass a control.<br><br></div><div>These social engineeri= ng attacks are exploiting the sense of duty that maintainers have with thei= r project and community in order to manipulate them. Pay attention to how i= nteractions make you feel. Interactions that create self-doubt, feelings of= inadequacy, of not doing enough for the project, etc. might be part of a s= ocial engineering attack.<br><br><a href=3D"https://openssf.org/blog/2024/0= 4/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-so= cial-engineering-takeovers-of-open-source-projects/">https://openssf.org/bl= og/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-ale= rt-for-social-engineering-takeovers-of-open-source-projects/</a><br></div><= div><div><br></div><span class=3D"gmail_signature_prefix">-- </span><br><di= v dir=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_signature">= Nelson Ferraz</div></div></div> --000000000000afa01a0617c86295--