An attacker has been impersonating a Linux Foundation community leader and contacting open-source developers on Slack as part of a phishing campaign to steal credentials and deploy malware, the Open Source Security Foundation (OpenSSF) said in an advisory April 7.The campaign has targeted members of the Linux Foundation’s ToDoGroup Slack workspace and related communities, wrote Christopher "CRob" Robinson in the advisory, chief technology officer and chief security architect at OpenSSF.Robinson said the attacker messages victims on Slack while impersonating the “well-known” community leader and lures them to click on a Google Sites link (sites[.]google[.]com/view/workspace-business/join), which redirects to a fake Google Workspace authentication flow.Socket reported that one of its engineers, a member of the ToDoGroup Slack workspace, received a message from the attacker, which claimed they were working on an AI tool for open-source projects and offered the target an exclusive opportunity to test it.The fake Google login process harvests email addresses and verification codes, after which the victim gets prompted to install a “Google certificate.”On Windows machines, installing this malicious root certificate via the browser trust dialog lets the attacker intercept encrypted traffic and further harvest credentials.On macOS devices, the certificate can also intercept traffic and steal credentials, but an additional script downloads and executes a malicious binary, “gapi,” from a remote IP address.“Executing the binary may result in full system compromise,” Robinson said.OpenSSF warns community members not to trust profiles based on name and Slack profile alone, and verify suspicious requests through a separate trusted communication channel.Developers are also recommended to be wary when clicking links, even when URLs may appear legitimate, as Socket notes that site[.]google[.]com is legitimate Google infrastructure that can be abused to redirect to malicious sites.OpenSSF says users should never install certificates from links nor run untrusted software or execute commands received through channels such as Slack or unfamiliar websites. The use of multi-factor authentication (MFA) for developers accounts is also encouraged.Those who clicked the attacker’s link or installed the malicious certificate are advised to immediately disconnect from their network, remove recently installed certificates, run security scans on their endpoints, rotate all credentials and revoke active sessions and tokens.This attack comes after a wave of social engineering campaigns targeting open-source maintainers, including those of high-impact projects with millions of weekly downloads such as “is,” “eslint-config-prettier,” “chalk,” and “axios.”Lead axios maintainer Jason Saayman disclosed after malicious updates were published through his npm account last weekend that he was social engineered via Slack by an attacker impersonating a company and ultimately lured to install a fake Microsoft Teams update.The axios attack has been attributed to the North Korean-affiliated threat actor UNC1069. Thus far, no connection between the axios attack and the attack described in OpenSSF’s advisory has been reported.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




