The EasyJSON Open Source Takeover

Hunted Labs Exposes Russian Ties to Popular Open Source Software Package

A seemingly innocuous open source project can become a critical security risk when control shifts into the wrong hands. Our threat intelligence report uncovers how easyjson, a widely used JSON parsing library, is controlled by developers whose organizations have ties to the Kremlin—posing a silent but potentially severe risk to software supply chains.

Inside This Report

How the EasyJSON Takeover Happened

A step-by-step analysis of the threat

Who Controls the Project Now

Unmasking the organizations behind the keyboard

The Security Implications

How this could expose organizations like yours to destructive backdoors and APTs

How To Mitigate the Risk

Actionable steps to secure your software supply chain

Don’t let your organization become the next victim of an open source takeover.

Enter your details to download the full report:

Cta ImageCta Image

Your Hunt Starts Now

Learn how DepsDiver and Entercept help organizations investigate and defend their software supply chains and critical systems.