Open source developers are under attack in a new, highly deceptive social engineering campaign.
According to a high-severity alert shared on the OpenSSF Siren mailing list on April 7, hackers are infiltrating Slack workspaces by impersonating a prominent Linux Foundation community leader.
Their goal is to trick developers into a multi-stage trap that culminates in malware installation and a complete system takeover.
A Deceptive Multi-Stage Attack
The attack heavily targets developer hubs like the TODO Group, a Linux Foundation workspace for open source professionals. The attacker reaches out via direct message using the stolen identity of a trusted community figure.
To grab the victim’s interest, they pitch an exclusive, private AI tool that supposedly predicts which project contributions will be merged before review. The attacker stresses that they are only sharing this tool with a select few.
From here, the attack adapts based on the victim’s operating system:
- On macOS, a hidden script downloads and runs a malicious file named “gapi” from a remote server, potentially leading to total system compromise.
- On Windows, the user is prompted to install the fake certificate through a standard browser security dialog.
In both scenarios, the malicious certificate allows the attackers to intercept encrypted web traffic and steal highly sensitive project data.

Protecting Developer Communities
This campaign is dangerous because it weaponizes the foundation of open source communities: trust. Developers are used to collaborating with project leads and foundation staff.
By convincingly impersonating a recognized leader, the attacker gains a massive social advantage before the victim even clicks a link.
This incident is part of a growing trend. Recently, security researchers identified a separate campaign targeting high-profile maintainers of major projects like Node.js, Fastify, and Lodash.

While it remains unclear whether the two attacks are linked to the same threat group, it is clear that hackers are increasingly hunting open-source maintainers through the platforms they rely on daily.
To stay safe in open source Slack communities, the OpenSSF recommends several critical defense measures:
- Verify identities out of band by confirming unusual requests via a separate communication channel, rather than relying on a profile picture.
- Never manually install root certificates, as legitimate web services rarely ask users to do this outside of official corporate IT setups.
- Avoid executing downloaded binaries, scripts, or code received via direct messages or unfamiliar websites.
- Treat unexpected security prompts or urgent authentication warnings with extreme caution.
According to Socket research, if you suspect this campaign has targeted you, disconnect your device from the network immediately.
Remove any newly installed certificates and run a comprehensive endpoint security scan. Finally, be sure to rotate all critical credentials, including GitHub passwords, SSH keys, and cloud access tokens, to lock the attackers out of your accounts.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.