Free Business Plan Upgrades for Open Source Maintainers
Brief
This week our Threat Research team tracked an active supply chain attack that took over a maintainer account and used it to push malware across the widely used keyv and cacheable packages, then spread to other maintainers through stolen npm tokens. Those packages sit deep in dependency trees and account for tens of millions of weekly downloads.
Attacks like this are getting more frequent, and open source maintainers are the ones on the receiving end. When an account takeover happens, the maintainer is often the last to find out and the first to deal with the fallout, usually alone. And usually for software they maintain for free.
Maintaining critical software now comes with a security burden that has outgrown what any volunteer can reasonably carry. Earlier this year a coordinated social engineering campaign hunted high-impact Node.
