Large-Scale Cyberattack Targets Open-Source Software, Affecting OpenAI and Others
A significant cyberattack has targeted open-source software projects, impacting organizations including OpenAI. The attack, identified as a 'supply chain' attack, involves compromising developer accounts to distribute malicious updates. According to cybersecurity firms StepSecurity and SafeDep, hackers managed to release over 630 malicious versions across 317 packages by taking control of a single developer's account. The attack aims to steal access credentials and propagate malware, with the Antv library owned by Alibaba among the affected packages. This incident highlights vulnerabilities in open-source software used globally.