OpenJS: “XZ Utils Cyberattack Likely Not an Isolated Incident” - Socket
OpenJS is warning open source project maintainers to be vigilant against social engineering takeover attempts after receiving one targeting the organization.“The recent attempted XZ Utils backdoor (CVE-2024-3094) may not be an isolated incident as evidenced by a similar credible takeover attempt intercepted by the OpenJS Foundation, home to JavaScript projects used by billions of websites worldwide,” OpenJS Foundation Executive Director Robin Bender said in a joint statement with the OpenSSF.The...
Read more at socket.dev