Social engineering attacks on open source developers are escalating
2026-04-08T14:51:54Z•29339c7c9c0be5124f86670e86d5eb1da7993a16f19cdd2ba6af324fc45f112b
ai-exploit-generationallen-bradleyanthropicaptchaos-malwarecloud-securitycveflatpakgenai-threats','edge-infrastructure','botnetsicsiranlinux-misconfigurationnorth-koreanpmopen-source-securityopensslotplcratrockwell-automationsandbox-escapesocial-engineeringsupply-chain-compromisevulnerabilitieszero-day
What happened
Multiple high-risk developments: North Korean actors used elaborate social engineering (fake Slack, cloned identity, fake Teams call) to trick an Axios maintainer into installing a RAT and injected malware into npm packages (wide impact); OpenSSF warns similar campaigns against open-source developers. U.S. agencies warn Iranian-affiliated APT activity targeting OT/PLC devices (including Rockwell Automation and Allen-Bradley) across energy, water and government networks. Chaos (Go-based) malware has expanded from routers to compromise misconfigured Linux cloud servers. Flatpak 1.16.4 fixes a CR
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 29339c7c9c0be5124f86670e86d5eb1da7993a16f19cdd2ba6af324fc45f112b
- Enrichment time
- 2026-04-08T14:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.