<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Muhammad Usman on foojay.io - Friends of OpenJDK</title><link>https://foojayio.github.io/website/today/author/muhammad-usman/</link><description>Articles written by Muhammad Usman on foojay.io - Friends of OpenJDK</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 03 Jul 2026 08:31:27 +0000</lastBuildDate><atom:link href="https://foojayio.github.io/website/today/author/muhammad-usman/index.xml" rel="self" type="application/rss+xml"/><item><title>This Dependency Update Looked Exactly Like an Account Takeover</title><link>https://foojayio.github.io/website/today/this-dependency-update-looked-exactly-like-an-account-takeover/</link><pubDate>Fri, 03 Jul 2026 08:31:27 +0000</pubDate><guid>https://foojayio.github.io/website/today/this-dependency-update-looked-exactly-like-an-account-takeover/</guid><description>&lt;p&gt;I pointed a scanner I have been building at an old Spring project, and it flagged javax.activation. The bump was 1.1-rev-1 to 1.1.1. Prior releases carried a GPG signature. This one did not.
&lt;img src="https://foojayio.github.io/website/today/this-dependency-update-looked-exactly-like-an-account-takeover/pr-comment-682x510.png" alt="git hub diff comment on PR" loading="lazy"&gt;
&lt;/p&gt;
&lt;br /&gt;
&lt;p&gt;If you have read the post-mortems of real supply-chain attacks, that pattern should make you sit up. A package that has signed its releases for years suddenly ships one unsigned. The boring explanation is a build pipeline change. The other explanation is that a different person is publishing now, and the signing key stayed behind with the old one. When ua-parser-js was hijacked in 2021, the malicious versions came from a compromised account. When event-stream went bad in 2018, it was a new maintainer nobody had vetted. The artifact looks fine. The metadata around it is what changed.&lt;/p&gt;</description></item></channel></rss>