Nation-state hackers infiltrate open-source software State-sponsored hackers from Russia, China and North Korea are systematically infiltrating the open-source software that powers over 90% of modern applications, according to a report released today by Strider Technologies. The intelligence firm's analysis reveals how adversarial nation-states are weaponizing platforms like GitHub to embed malicious code into widely-used software repositories, creating cascading security risks across industries and governments worldwide. Strider's research identified contributors with direct affiliations to sanctioned Russian and Chinese entities actively contributing to critical open-source projects. More than 21% of contributors to openvino-genai—an AI inference toolkit downloaded over one million times—were flagged as presenting nation-state security threats. Two contributors were linked to MFI Soft and Positive Technologies, Russian companies sanctioned by the U.S. for supporting intelligence collection and cyberattacks. Sophisticated Long-Term Infiltration The report documents how advanced persistent threat groups like APT41 from China, Russia's Cozy Bear, and North Korea's Lazarus Group are employing patient, years-long strategies to gain credibility within open-source communities<a target="_blank" href="https://www.washingtontimes.com/news/2025/aug/4/russian-chinese-coders-secretly-insert-malicious-code-open-source/"></a><a target="_blank" href="https://www.nextgov.com/cybersecurity/2025/08/foreign-adversaries-are-trying-weaponize-open-source-software-report-finds/407190/"></a>. "Actors will spend years building respectable reputations before adding their own harmful code," explained Paige Waltz, Strider's Director of Global Communications<a target="_blank" href="https://www.washingtontimes.com/news/2025/aug/4/russian-chinese-coders-secretly-insert-malicious-code-open-source/"></a>. Some attackers contribute 40 to 50 times to a codebase before injecting malicious backdoors, making detection extremely difficult<a target="_blank" href="https://www.washingtontimes.com/news/2025/aug/4/russian-chinese-coders-secretly-insert-malicious-code-open-source/"></a>. North Korea's Lazarus Group has intensified these efforts, with Sonatype detecting 234 unique malicious packages tied to the group in the first half of 2025 alone, potentially compromising 36,000 developers globally<a target="_blank" href="https://siliconangle.com/2025/07/30/lazarus-turns-open-source-weapon-latest-global-espionage-push/"></a><a target="_blank" href="https://www.infosecurity-magazine.com/news/200-malicious-open-source-lazarus/"></a>. The group's Operation Marstech Mayhem campaign demonstrates this evolution, using fake GitHub repositories to distribute the sophisticated "Marstech1" implant targeting cryptocurrency wallets and credentials<a target="_blank" href="https://securityscorecard.com/blog/lazarus-group-targets-developers-through-npm-packages-and-supply-chain-attacks/"></a><a target="_blank" href="https://devops.com/north-koreas-lazarus-group-targets-developers-supply-chain/"></a>. Billion-Dollar Impact from Past Attacks The vulnerability of open-source software has already proven costly. The 2021 Log4Shell vulnerability exploitation, involving actors from China, North Korea, Iran and Turkey, cost affected organizations upwards of $90,000 per incident response<a target="_blank" href="https://www.washingtontimes.com/news/2025/aug/4/russian-chinese-coders-secretly-insert-malicious-code-open-source/"></a>. Nearly two years after the incident, 72% of affected organizations were still reporting active exploitation events<a target="_blank" href="https://www.washingtontimes.com/news/2025/aug/4/russian-chinese-coders-secretly-insert-malicious-code-open-source/"></a>. Recent incidents like the XZ Utils backdoor attempt in February 2024 highlight the sophisticated nature of these threats<a target="_blank" href="https://www.nextgov.com/cybersecurity/2025/08/foreign-adversaries-are-trying-weaponize-open-source-software-report-finds/407190/"></a><a target="_blank" href="https://cyberscoop.com/unverified-code-is-the-next-national-security-threat-op-ed/"></a>. The attacker, using the pseudonym "Jia Tan," spent years building trust within the Linux community before attempting to plant a backdoor in compression software used across numerous systems worldwide<a target="_blank" href="https://cyberscoop.com/unverified-code-is-the-next-national-security-threat-op-ed/"></a>. "Nation-states like China and Russia are exploiting this visibility gap," said Greg Levesque, CEO of Strider Technologies<a target="_blank" href="https://www.striderintel.com/newsroom/lying-in-wait-new-strider-report-finds-high-risk-contributors-connected-to-adversarial-nation-states-in-open-source-software-ecosystems/"></a><a target="_blank" href="https://www.prnewswire.com/news-releases/lying-in-wait-new-strider-report-finds-high-risk-contributors-connected-to-adversarial-nation-states-in-open-source-software-ecosystems-302520075.html"></a>. "Individuals are lying in wait, building credibility in the ecosystem with the power to introduce malicious code with devastating downstream effects."