Security Researchers Warn a Widely Used Open Source Tool Poses a ‘Persistent’ Risk to the US

Concerns Raised Over Russian-Linked Open Source Tool Used in US Critical Infrastructure
Photo: WIRED

Concerns Raised Over Russian-Linked Open Source Tool Used in US Critical Infrastructure

Security researchers from Hunted Labs have raised concerns about the open-source software easyjson, a code serialization tool for the Go programming language, which is widely used by the US government and major sectors such as finance, technology, and healthcare. The main issue stems from easyjson’s management by Russian developers affiliated with VK Group, whose CEO, Vladimir Kiriyenko, is under US sanctions for ties to the Kremlin. Although no vulnerabilities have been found in the easyjson code, experts warn that its control by a Russian entity with a history of alignment with the Russian government could pose a persistent national security risk, especially given Russia’s record of state-backed cyberattacks. The package is hosted on GitHub by a MailRu account, now part of VK, and most updates occurred before 2020. The article highlights the growing scrutiny of foreign open-source software amid geopolitical tensions and the threat of supply chain attacks, referencing past incidents where trusted open-source projects were compromised. Experts emphasize the importance of risk-aware decision-making when integrating open-source tools into critical systems, noting that while open source remains valuable, the changing geopolitical landscape necessitates greater vigilance.

Leave a Reply

Your email address will not be published. Required fields are marked *