Social engineering attacks on open source developers are escalating

2026-04-08T14:51:54Z29339c7c9c0be5124f86670e86d5eb1da7993a16f19cdd2ba6af324fc45f112b
ai-exploit-generationallen-bradleyanthropicaptchaos-malwarecloud-securitycveflatpakgenai-threats','edge-infrastructure','botnetsicsiranlinux-misconfigurationnorth-koreanpmopen-source-securityopensslotplcratrockwell-automationsandbox-escapesocial-engineeringsupply-chain-compromisevulnerabilitieszero-day

What happened

Multiple high-risk developments: North Korean actors used elaborate social engineering (fake Slack, cloned identity, fake Teams call) to trick an Axios maintainer into installing a RAT and injected malware into npm packages (wide impact); OpenSSF warns similar campaigns against open-source developers. U.S. agencies warn Iranian-affiliated APT activity targeting OT/PLC devices (including Rockwell Automation and Allen-Bradley) across energy, water and government networks. Chaos (Go-based) malware has expanded from routers to compromise misconfigured Linux cloud servers. Flatpak 1.16.4 fixes a CR

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
29339c7c9c0be5124f86670e86d5eb1da7993a16f19cdd2ba6af324fc45f112b
Enrichment time
2026-04-08T14:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Social engineering attacks on open source developers are escalating · Baitaphish