How to combat the new threats in open-source libraries
The recent breach of GitHub Inc. that gave attackers access to around 4,000 of the platform’s internal code repositories dramatizes the growing threats from malicious actors who bury malware in open-source software libraries. Supply chains are coveted targets for cyberattacks, and threats have been amplified recently by how quickly they can be introduced. Perpetrators have […] The post How to…
The recent breach of GitHub Inc. has exposed the growing threats posed by malicious actors who insert malware into open-source software libraries. With the rise of AI technology, attackers can now carry out these attacks on a larger scale, targeting multiple organizations, individuals, and devices simultaneously. This development has been made possible by the ease with which AI enables "vibe coding," allowing users to download and install packages from the cloud without proper scrutiny.
To combat these emerging threats, organizations should implement four key principles: restrict downloads, enforce strong policies, technical controls, and file locking. By restricting downloads, organizations can limit the scope of potential attacks and hold themselves accountable when issues arise. This can be achieved by vetting packages and enforcing policies around which open-source packages are allowed, ensuring all installed software goes through internal reviews.
Additionally, organizations must employ technical controls to detect malicious code during the installation process. This can be challenging as malicious code often lacks apparent indicators at the time of installation. To address this, security leaders should implement technical controls that enable behavioral analysis at the time of installation.
Another crucial step is implementing file locking and version pinning when introducing new packages into the organization. This practice ensures that only approved versions of software packages are used, preventing unauthorized updates that could introduce vulnerabilities. Moreover, it provides additional time to assess potential damage caused by newer versions.
Organizations should also reassess the developer tooling allowed within their systems. While safeguarding end-user devices is essential, developers should not be granted unrestricted access to system tooling. Instead, a set of approved, vetted extensions should be designated for use by developers. Developers seeking to use new extensions must undergo a security review process, ensuring that only trusted extensions are integrated into the organization's workflow.
Finally, leaders must remain vigilant and diligent about ascertaining code security. Historically, open-source library attacks relied on social engineering tactics to convince users to download malicious packages. However, with the advent of AI, attackers now exploit compromised credentials to push packages out to unsuspecting users.
Code signing, once considered a reliable security measure, is no longer foolproof, as signing keys can be stolen within the build pipeline itself. As a result, cybersecurity professionals must be more vigilant than ever in identifying potential threats and protecting their organizations from these evolving attacks.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.