A seemingly innocuous open source project can become a critical security risk when control shifts into the wrong hands. Our threat intelligence report uncovers how easyjson, a widely used JSON parsing library, is controlled by developers whose organizations have ties to the Kremlin—posing a silent but potentially severe risk to software supply chains.