
Security Researchers Warn a Widely Used Open Source Tool Poses a 'Persistent' Risk to the US
May 5, 2025 6:00 AM The open source software easyjson is used by the US government and American companies. But its ties to Russia's VK, whose CEO has been sanctioned, have researchers sounding the alarm. A worker inspects server racks at a data center inside the VK Company Ltd. office in Moscow, Russia, on Wednesday, Jan. 19, 2022. Photograph:Since Russian troops invaded Ukraine more than three years ago, Russian technology companies and executives have been widely sanctioned for supporting the Kremlin. That includes Vladimir Kiriyenko, the son of one of Vladimir Putin's top aides and the CEO of VK Group, which runs VK, Russia's Facebook equivalent that has increasingly shifted towards the regime's repressive positioning.
Now cybersecurity researchers are warning that a widely used piece of open source code—which is linked to Kiriyenko's company and managed by Russian developers—may pose a 'persistent' national security risk to the United States. The open source software (OSS), called easyjson, has been widely used by the US Department of Defense and 'extensively' across software used in the finance, technology, and healthcare sectors, say researchers at security company Hunted Labs, which is behind the claims. The fear is that Russia could alter easyjson to steal data or otherwise be abused.
'You have this really critical package that's basically a linchpin for the cloud native ecosystem, that's maintained by a group of individuals based in Moscow belonging to an organization that has this suspicious history,' says Hayden Smith, a cofounder at Hunted Labs.
For decades, open source software has underpinned large swathes of the technology industry and the systems people rely on day to day. Open source technology allows anyone to see and modify code, helping to make improvements, detect security vulnerabilities, and apply independent scrutiny that's absent from the closed tech of corporate giants. However, the fracturing of geopolitical norms and the specter of stealthy supply chain attacks has led to an increase in questions about risk levels of "foreign" code.
Easyjson is a code serialization tool for the Go programming language and is often used across the wider cloud ecosystem, being present in other open source software, according to Hunted Labs. The package is hosted on GitHub by a MailRu account, which is owned by VK after the mail company rebranded itself in 2021. The VK Group itself is not sanctioned. Easyjson has been available on Github since 2016, with most of its updates coming before 2020. Kiriyenko became the CEO of VK Group in December 2021 and was sanctioned in February 2022.
Hunted Labs' analysis shared with WIRED shows the most active developers on the project in recent years have listed themselves as being based in Moscow. Smith says that Hunted Labs has not identified vulnerabilities in the easyjson code.
However, the link to the sanctioned CEO's company, plus Russia's aggressive state-backed cyberattacks, may increase potential risks, Smith says. Research from Hunted Labs details how code serialization tools could be abused by malicious hackers. 'A Russian-controlled software package could be used as a 'sleeper cell' to cause serious harm to critical US infrastructure or for espionage and weaponized influence campaigns,' it says.
'Nation states take on a strategic positioning,' says George Barnes, a former deputy director at the National Security Agency, who spent 36 years at the NSA and now acts as a senior advisor and investor in Hunted Labs. Barnes says that hackers within Russia's intelligence agencies could see easyjson as a potential opportunity for abuse in the future.
'It is totally efficient code. There's no known vulnerability about it, hence no other company has identified anything wrong with it,' Barnes says. 'Yet the people who actually own it are under the guise of VK, which is tight with the Kremlin,' he says. 'If I'm sitting there in the GRU or the FSB and I'm looking at the laundry list of opportunities… this is perfect. It's just lying there,' Barnes says, referencing Russia's foreign military and domestic security agencies.
VK Group did not respond to WIRED's request for comment about easyjson. The US Department of Defense did not respond to a request for comment about the inclusion of easyjson in its software setup.
'NSA does not have a comment to make on this specific software,' a spokesperson for the National Security Agency says. 'The NSA Cybersecurity Collaboration Center does welcome tips from the private sector—when a tip is received, NSA triages the tip against our own insights to fully understand the threat and, if corroborated, share any relevant mitigations with the community.' A spokesperson for the US Cybersecurity and Infrastructure Security Agency, which has faced upheaval under the second Trump administration, says: 'We are going to refer you back to Hunted Labs.'
GitHub, a code repository owned by Microsoft, says that while it will investigate issues and take action where its policies are broken, it is not aware of malicious code in easyjson and VK is not sanctioned itself. Other tech companies' treatment of VK varies. After Britain sanctioned the leaders of Russian banks who own stakes in VK in September 2022, for example, Apple removed its social media app from its App Store.
Dan Lorenc, the CEO of supply chain security firm Chainguard, says that with easyjson, the connections to Russia are in 'plain sight' and that there is a 'slightly higher' cybersecurity risk than those of other software libraries. He adds that the red flags around other open source technology may not be so obvious.
'In the overall open source space, you don't necessarily even know where people are most of the time,' Lorenc says, pointing out that many developers do not disclose their identity or locations online, and even if they do, it is not always possible to verify the details are correct. 'The code is what we have to trust and the code and the systems that are used to build that code. People are important, but we're just not in a world where we can push the trust down to the individuals,' Lorenc says.
As Russia's full-scale invasion of Ukraine has unfolded, there has been increased scrutiny on the use of open source systems and the impact of sanctions upon entities involved in the development. In October last year, a Linux kernel maintainer removed 11 Russian developers who were involved in the open souce project, broadly citing sanctions as the reason for the change. Then in January this year, the Linux Foundation issued guidance covering how international sanctions can impact open source, saying developers should be cautious of who they interact with and the nature of interactions.
The shift in perceived risk is coupled with the threat of supply chain attacks. Last year, corporate developers and the open source world were rocked as a mysterious attacker known as Jia Tan stealthily installed a backdoor in the widely used XZ Utils software, after spending two years diligently updating it without any signs of trouble. The backdoor was only discovered by chance.
'Years ago, OSS was developed by small groups of trusted developers who were known to one another,' says Nancy Mead, a fellow of the Carnegie Mellon University Software Engineering Institute. 'In that time frame, no one expected a trusted developer of being a hacker, and the relatively slower pace provided time for review. These days, with automatic release, incorporation of updates, and the wide usage of OSS, the old assumptions are no longer valid.'
Scott Hissam, a senior member of technical staff also from the Carnegie Software Engineering Institute, says there can often be consideration about how many maintainers and the number of organizations that work on an open source project, but there is currently not a 'mass movement' to consider other details about OSS projects. 'However, it is coming, and there are several activities that collect details about OSS projects, which OSS consumers can use to get more insight into OSS projects and their activities,' Hissam says, pointing to two examples.
Hunted Lab's Smith says he is currently looking into the provenance of other open source projects and the risks that could come with them, including scrutinizing countries known to have carried out cyberattacks against US entities. He says he is not encouraging people to avoid open source software at all, more that risk considerations have shifted over time. 'We're telling you to just make really good risk informed decisions when you're trying to use open source,' he says. 'Open source software is basically good until it's not.'
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles
Yahoo
21 minutes ago
- Yahoo
Atlanta dad's car now worth $30K — but he still owes $57K. Why Ramsey Show hosts say he's got to take a ‘bath'
Terrence from Atlanta has a budget problem, and he knows it. The Georgia father recently called in to The Ramsey Show seeking advice on how to get rid of his car, a 2021 Kia Stinger GT2 that costs him $1,200 a month. He also pays $2,000 in child support every month — a financial burden that leaves him with little breathing room despite earning a six-figure salary. Thanks to Jeff Bezos, you can now become a landlord for as little as $100 — and no, you don't have to deal with tenants or fix freezers. Here's how I'm 49 years old and have nothing saved for retirement — what should I do? Don't panic. Here are 6 of the easiest ways you can catch up (and fast) Nervous about the stock market in 2025? Find out how you can access this $1B private real estate fund (with as little as $10) 'I make $10,000 a month,' Terrence told co-hosts Ken Coleman and Dr. John Delony. 'I bring home $5,200 after taxes and child support.' Terrence bought the Stinger for about $60,000 — rolling in negative equity from a previous vehicle. Two years later and he still owes $57,000, but the car is now only worth about $30,000. 'Oh boy, that's a bath!' Coleman exclaimed. 'That is a bat right there.' Terrence's situation isn't rare. Unfortunately, many Americans find themselves 'car poor' — trapped by high monthly payments, inflated prices and interest rates that stretch already-thin budgets. According to CarEdge, the average price of a new car in the U.S. hovers around $48,699. Meanwhile, Experian reports the average monthly car payment for new vehicles sits at $742 as of Q4 2024. Interest rates on auto loans are also elevated, with new car buyers paying an average of 7.1% in Q1 2025, according to USA Today. All of this has led to Americans accumulating $1.64 trillion in auto loan debt as of Q1 2025, according to Trade Economics. Those numbers don't even factor in insurance, gas or maintenance costs. And with 20% of new car buyers now paying over $1,000 a month, Terrence is among a growing cohort of American drivers underwater on their loans. Read more: Want an extra $1,300,000 when you retire? Dave Ramsey says — and that 'anyone' can do it Terrence's question for the co-hosts was simple: what's the fastest, least painful way out of this situation? In order to give the co-hosts a complete picture of his finances, Terrence said he typically has between $1,300 and $1,400 remaining every month after paying his child support and other expenses. The co-hosts offered Terrence two potential escape routes. One option is to aggressively pay off the car over a long period of time by throwing $3,000 a month at the debt. However, that route might include some extreme budgeting and maybe even a few overtime shifts for Terrence. "If you take that $1,200 a month [car] payment, you take that $1,300 extra and you go through your budget with a magnifying glass. You stop going out for a season, and let's say you can scrounge up $3,000 [per month] that includes this $1,200. You can pay this thing off,' Deloney said. The other route calls for Terrence to sell the car now for around $30,000 and buy a reliable used vehicle — like a high-mileage Toyota or a Buick, which Terrence once owned and loved — for about $7,500, and then pay off a big chunk of the auto loan balance with the roughly $22,000 remaining from the sale of the car. This would leave Terrence with roughly $35,000 left on the auto loan, which means he wouldn't be out of the woods just yet. Either way, Terrence is going to have to pull himself up by his boot straps and create a frugal budget in order to get out of this financial hole. Ultimately, the co-hosts applauded Terrence's honesty and determination to change course. 'I've got a daughter who's about to go to college, so I want to have the money," Terrence said. Coleman and Delony's final piece of advice? Ditch the debt, drive a modest car and stay focused on long-term goals. Rich, young Americans are ditching the stormy stock market — here are the alternative assets they're banking on instead How much cash do you plan to keep on hand after you retire? Here are 3 of the biggest reasons you'll need a substantial stash of savings in retirement Robert Kiyosaki warns of a 'Greater Depression' coming to the US — with millions of Americans going poor. But he says these 2 'easy-money' assets will bring in 'great wealth'. How to get in now Here are 5 'must have' items that Americans (almost) always overpay for — and very quickly regret. How many are hurting you? Like what you read? Join 200,000+ readers and get the best of Moneywise straight to your inbox every week. This article provides information only and should not be construed as advice. It is provided without warranty of any kind. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data


Boston Globe
21 minutes ago
- Boston Globe
US imposes sanctions on a Palestinian NGO and other charities, accusing them ties to militant groups
The federal government claims that Addameer 'has long supported and is affiliated' with the Popular Front for the Liberation of Palestine, a secular, left-wing movement with a political party and an armed wing that has carried out deadly attacks against Israelis. Israel and the United States have labeled the PFLP a terrorist organization. Get Starting Point A guide through the most important stories of the morning, delivered Monday through Friday. Enter Email Sign Up Addameer did not immediately have a comment on the sanctions. Advertisement Israel has alleged that Addameer funds terrorism, a claim that the United Nations previously said it could not support with compelling evidence. In a 2022 The organization also works with Amnesty International, Human Rights Watch and is a member of the World Organization Against Torture. Israel's 2022 storming of Addameer's offices, prompted a rebuke from the UN, who said in a statement that Israel had not provided convincing evidence to support the claim. The UN said Addameer was conducting 'critical human rights, humanitarian and development work in the Occupied Palestinian Territory.' Advertisement In February, Zachor Legal Institute, an Israeli-American advocacy group that says it focuses on combatting antisemitism and terrorism, requested Addameer be added to Treasury's sanctions list. Marc Greendorfer, president of Zachor Legal Institute said in an email to the Associated Press that his group is 'very pleased to see Treasury following up on our request.' He said the federal government should act 'to prevent hostile foreign actors from spreading hate and violence in the United States. We applaud Treasury's action and encourage Treasury to expand its focus to the other groups that we identified.' Other entities hit with sanctions Tuesday include: The Gaza-based charity Al Weam Charitable Society and its leader The Turkish charity Filistin Vakfi and its leader El Baraka Association for Charitable and Humanitarian Work and its leader The Netherlands-based Israa Charitable Foundation Netherlands and two employees The Italy-based Associazione Benefica La Cupola d'Oro A Because the majority of crowdfunding activity is legitimate, 'this status can make it more difficult for law enforcement attempting to investigate potential (terrorist financing) cases with a crowdfunding and online fundraising nexus,' the report said. Frankel reported from Jerusalem.

Wall Street Journal
29 minutes ago
- Wall Street Journal
Fortress Reacts to the Tillis-Hern Tort Reform
We take issue with your editorial 'Ending a Tax Break for Lawsuits' (June 5). You assert that 'foreign investors in U.S. litigation don't have to pay tax on lawsuit proceeds because the tax code exempts foreigners from paying U.S. capital-gains tax, and their legal payouts are treated as capital gains.' But this isn't true for Fortress, an American company, whose investment decisions are made by our U.S. leadership. We have never allowed any non-U.S. investor to treat recoveries from legal assets as exempt from tax by characterizing income as capital gains. Investments in U.S. legal assets by our funds are subject to the usual corporate or ordinary income-tax rates and rules. American corporations use legal financing, like that offered by some Fortress-managed funds, because using the court system isn't free. This financing isn't about 'harming U.S. businesses' or targeting corporations. It helps American businesses spend less of their money on pursuing justified claims and more on job creation and economic growth.