Navigation
Search
|
Defense Department Reportedly Relies On Utility Written by Russian Dev
Thursday August 28, 2025. 12:40 AM , from Slashdot
![]() Hunted Labs told us that it didn't speak to Malinochkin prior to publication of its report today, and that it found no ties between him and any threat actor. According to Hunted Labs, fast-glob is downloaded more than 79 million times a week and is currently used by more than 5,000 public projects in addition to the DoD systems and Node.js container images that include it. That's not to mention private projects that might use it, meaning that the actual number of at-risk projects could be far greater. While fast-glob has no known CVEs, the utility has deep access to systems that use it, potentially giving Russia a number of attack vectors to exploit. Fast-glob could attack filesystems directly to expose and steal info, launch a DoS or glob-injection attack, include a kill switch to stop downstream software from functioning properly, or inject additional malware, a list Hunted Labs said is hardly exhaustive. Hunted Labs cofounder Haden Smith told The Register that the ties are cause for concern. 'Every piece of code written by Russians isn't automatically suspect, but popular packages with no external oversight are ripe for the taking by state or state-backed actors looking to further their aims,' Smith told us in an email. 'As a whole, the open source community should be paying more attention to this risk and mitigating it.' Hunted Labs said that the simplest solution for the thousands of projects using fast-glob would be for Malinochkin to add additional maintainers and enhance project oversight, as the only other alternative would be for anyone using it to find a suitable replacement. 'Open source software doesn't need a CVE to be dangerous,' Hunted Labs said of the matter. 'It only needs access, obscurity, and complacency,' something we've noted before is an ongoing problem for open source projects. This serves as another powerful reminder that knowing who writes your code is just as critical as understanding what the code does,' Hunted Labs concluded. Read more of this story at Slashdot.
https://tech.slashdot.org/story/25/08/27/2026245/defense-department-reportedly-relies-on-utility-wri...
Related News |
25 sources
Current Date
Aug, Thu 28 - 12:41 CEST
|